Re: [RFC][Under discussion] Arbitrary string interpolation
| From: | Theodore Brown | Date: | Fri, 18 Mar 2022 04:49:21 +0000 |
| Subject: | Re: [RFC][Under discussion] Arbitrary string interpolation | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-117367@lists.php.net to get a copy of this message | ||
On Thu, Mar 17, 2022 at 5:40 PM Tobias Nyholm <tobias.nyholm@gmail.com> wrote:
> On Thu, 17 Mar 2022, 23:27 Ilija Tovilo, <tovilo.ilija@gmail.com> wrote:
>
>> Hi everyone
>>
>> I'd like to start discussion on a new RFC for arbitrary string
>> interpolation.
>> https://wiki.php.net/rfc/arbitrary_string_interpolation
>>
>> Let me know what you think.
>
> That is a cool idea.
> But I am not a big fan of having code in strings.
> Wouldn’t this open the door to all kinds of new attacks?
Do you have an example of a new kind of attack this would allow?
The proposal doesn't enable interpolation of strings coming from
a database or user input - it only applies to string literals
directly in PHP code.
Personally I'm really looking forward to having this functionality.
Just a couple days ago I wanted to call a function in an interpolated
string, and it was really annoying to have to wrap the function in a
closure in order to use it.
If this RFC is accepted I'd be able to replace code like this:
$name = "Theodore Brown";
$strlen = fn(string $string): int => strlen($string);
echo "{$name} has a length of {$strlen($name)}.";
with
$name = "Theodore Brown";
echo "{$name} has a length of {$:strlen($name)}.";
Sincerely,
Theodore