Re: [RFC] Name issue - is_literal/is_trusted
| From: | Guilliam Xavier | Date: | Thu, 24 Jun 2021 08:34:18 +0000 |
| Subject: | Re: [RFC] Name issue - is_literal/is_trusted | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-115100@lists.php.net to get a copy of this message | ||
On Thu, Jun 24, 2021 at 9:14 AM Scott Arciszewski <scott@paragonie.com>
wrote:
> On Thu, Jun 24, 2021 at 2:10 AM Stephen Reay <php-lists@koalephant.com>
> wrote:
>
> > I would absolutely make use of a function that tells me if the string
> given is in fact from something controlled by the developer. But once that
> same string can also include input from the request or the environment or
> whatever by nature of integers, the function becomes useless for the stated
> purpose.
>
> Why not two functions then?
>
> - is_noble_string() -- more restrictive
> - is_noble() -- YOLO
>
I was going to ask basically the same [with different names] a few days ago
("why can't we have both?"), but then remembered
https://externals.io/message/114835#114951
, esp. the end:
"""
And to support having 2 functions, we would need 2 flags on strings. These
flags are limited, and managing 2 flags would affect performance.
"""
Regards,
--
Guilliam Xavier