note 43754 modified in language.operators.comparison by danbrown

From: Date: Thu, 18 Jun 2009 14:16:06 +0000
Subject: note 43754 modified in language.operators.comparison by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-157090@lists.php.net to get a copy of this message
For converted Perl programmers: use strict comparison operators (===, !==) in place of string comparison operators (eq, ne). Don't use the simple equality operators (==, !=), because ($a == $b) will return TRUE in many situations where ($a eq $b) would return FALSE. For instance... "mary" == "fred" is FALSE, but "+010" == "10.0" is TRUE (!) In the following examples, none of the strings being compared are identical, but because PHP *can* evaluate them as numbers, it does so, and therefore finds them equal... <?php echo ("007" == "7" ? "EQUAL" : "not equal"); // Prints: EQUAL // Surrounding the strings with single quotes (') instead of double // quotes (") to ensure the contents aren't evaluated, and forcing // string types has no effect. echo ( (string)'0001' == (string)'+1.' ? "EQUAL" : "not equal"); // Prints: EQUAL // Including non-digit characters (like leading spaces, "e", the plus // or minus sign, period, ...) can still result in this behavior, if // a string happens to be valid scientific notation. echo (' 131e-2' == '001.3100' ? "EQUAL" : "not equal"); // Prints: EQUAL ?> If you're comparing passwords (or anything else for which "near" precision isn't good enough) this confusion could be detrimental. Stick with strict comparisons... <?php // Same examples as above, using === instead of == echo ("007" === "7" ? "EQUAL" : "not equal"); // Prints: not equal echo ( (string)'0001' === (string)'+1.' ? "EQUAL" : "not equal"); // Prints: not equal echo (' 131e-2' === '001.3100' ? "EQUAL" : "not equal"); // Prints: not equal ?> --was-- For converted Perl programmers: use strict comparison operators (===, !==) in place of string comparison operators (eq, ne). Don't use the simple equality operators (==, !=), because ($a == $b) will return TRUE in many situations where ($a eq $b) would return FALSE. For instance... "mary" == "fred" is FALSE, but "+010" == "10.0" is TRUE (!) In the following examples, none of the strings being compared are identical, but because PHP *can* evaluate them as numbers, it does so, and therefore finds them equal... <? echo ("007" == "7" ? "EQUAL" : "not equal"); // Prints: EQUAL // Surrounding the strings with single quotes (') instead of double // quotes (") to ensure the contents aren't evaluated, and forcing // string types has no effect. echo ( (string)'0001' == (string)'+1.' ? "EQUAL" : "not equal"); // Prints: EQUAL // Including non-digit characters (like leading spaces, "e", the plus // or minus sign, period, ...) can still result in this behavior, if // a string happens to be valid scientific notation. echo (' 131e-2' == '001.3100' ? "EQUAL" : "not equal"); // Prints: EQUAL ?> If you're comparing passwords (or anything else for which "near" precision isn't good enough) this confusion could be detrimental. Stick with strict comparisons... <? // Same examples as above, using === instead of == echo ("007" === "7" ? "EQUAL" : "not equal"); // Prints: not equal echo ( (string)'0001' === (string)'+1.' ? "EQUAL" : "not equal"); // Prints: not equal echo (' 131e-2' === '001.3100' ? "EQUAL" : "not equal"); // Prints: not equal ?> http://php.net/manual/en/language.operators.comparison.php

« previous php.notes (#157090) next »