Re: Let's allow eval() to be turned off in PHP 8
| From: | Ian Littman | Date: | Tue, 26 Nov 2019 16:15:58 +0000 |
| Subject: | Re: Let's allow eval() to be turned off in PHP 8 | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-107863@lists.php.net to get a copy of this message | ||
Looks like PHPUnit only uses eval() for mock objects, and Twig only uses it
as a last line of defense for building templates. Still breakages, but not
of the entire packages (at least those packages) from what I can see.
That said, I agree that eval() should stay enabled by default, as too much
breaks if we did the opposite. That way, folks can opt into a hardened
environment (at least in this respect) once they've determined that doing
so won't break their software.
On Tue, Nov 26, 2019 at 10:01 AM Ken Stanley <dohpaz@gmail.com> wrote:
>
> So long as the default behavior is to leave it available, I'm okay with
> this. Any app
> that relies on twig/twig, phpunit/phpunit, many symfony packages,
> dompdf/dompdf,
> etc relies on being able to use eval().
>