Re: Re: [RFC] is_literal
| From: | Craig Francis | Date: | Fri, 18 Jun 2021 11:22:18 +0000 |
| Subject: | Re: Re: [RFC] is_literal | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-114947@lists.php.net to get a copy of this message | ||
On Fri, 18 Jun 2021 at 11:45 am, Guilliam Xavier <guilliam.xavier@gmail.com>
wrote:
> IIUC, with the addition of integers, the function will return true for e.g.
>
'SELECT * FROM foo LIMIT ' . (int)$limit even if
> $limit doesn't come from
> a "static" value (e.g. random_int() or even
> $_GET['limit'])
Yes, that’s correct.
Supporting integers from any source helps with adoption, and we cannot find
any security issues (it’s a fairly small change to the RFC, and that
prompted the new name, especially as the original is_literal wasn’t
perfect).