Re: [RFC][Under discussion] Arbitrary string interpolation

From: Date: Fri, 18 Mar 2022 04:49:21 +0000
Subject: Re: [RFC][Under discussion] Arbitrary string interpolation
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-117367@lists.php.net to get a copy of this message
On Thu, Mar 17, 2022 at 5:40 PM Tobias Nyholm <tobias.nyholm@gmail.com> wrote: > On Thu, 17 Mar 2022, 23:27 Ilija Tovilo, <tovilo.ilija@gmail.com> wrote: > >> Hi everyone >> >> I'd like to start discussion on a new RFC for arbitrary string >> interpolation. >> https://wiki.php.net/rfc/arbitrary_string_interpolation >> >> Let me know what you think. > > That is a cool idea. > But I am not a big fan of having code in strings. > Wouldn’t this open the door to all kinds of new attacks? Do you have an example of a new kind of attack this would allow? The proposal doesn't enable interpolation of strings coming from a database or user input - it only applies to string literals directly in PHP code. Personally I'm really looking forward to having this functionality. Just a couple days ago I wanted to call a function in an interpolated string, and it was really annoying to have to wrap the function in a closure in order to use it. If this RFC is accepted I'd be able to replace code like this: $name = "Theodore Brown"; $strlen = fn(string $string): int => strlen($string); echo "{$name} has a length of {$strlen($name)}."; with $name = "Theodore Brown"; echo "{$name} has a length of {$:strlen($name)}."; Sincerely, Theodore

« previous php.internals (#117367) next »