note 24571 deleted from function.eval by victor

From: Date: Sat, 12 Jun 2004 22:39:01 +0000
Subject: note 24571 deleted from function.eval by victor
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-70997@lists.php.net to get a copy of this message
Note Submitter: johnmott59@hotmail.com ---- eval is nice for handling user calculations instead of writing a recursive descent parser. The note above warns about the dangers of this, but by value checking the expression you can be ok. I allow users to enter an expression with one of 9 variables named 'q1' to 'q9'. They can use the arithmetic operators, digits and the 'q' variables. Before executing the eval() I convert all of those things to blanks in a copy of the expression. If anything is left over its an invalid expression and I don't execute it. /* * Validate, this string should only contain digits, operators and q variables */ $sTemp = strtolower($formula); $pat = "(q1|q2|q3|q4|q5|q6|q7|q8|q9)"; $replace = ""; $sTemp = ereg_replace($pat,$replace,$sTemp); /* * Convert digits and operators to blank */ $sTemp = strtr($sTemp,"0123456789-+/*()"," "); /* * If the calculation isn't null its invalid */ if (trim($sTemp) != "") $result = "<font color=red> Invalid calculation </font>";

« previous php.notes (#70997) next »