RE: [PEAR-DEV] Package proposal: Net_Ip
| From: | Lukas Smith | Date: | Fri, 30 May 2003 13:05:17 +0000 |
| Subject: | RE: [PEAR-DEV] Package proposal: Net_Ip | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-16831@lists.php.net to get a copy of this message | ||
> From: Stefan Walk [mailto:swalk@prp.physik.tu-darmstadt.de]
> Sent: Friday, May 30, 2003 2:58 PM
> On Fri, May 30, 2003 at 02:15:23PM +0200, cagrET wrote:
> > Maybe before asking this question, you could look at the code and
> example ?
> > is it so hard ?
>
> Answering the question would have taken you just as much time.
Well we are getting an increasing amount of contributions, which is a
good thing (tm). This however means that it a lot of work to look at
each proposal. Therefore its important that people who make a proposal
also check for existing package that might overlap in functionality
(ideally the person making the proposal would verify this himself).
> The code has quite a few drawbacks by the way.
Now we are coming to the benefits of making a package proposal:
Peer review.
I can say that since working on PEAR code I have become radically better
in PHP coding. So this is why it makes sense to make a good proposal: to
get good peer review.
> Client-ip and http-x-forwarded-for headers can be set by anyone,
> and your script would assume that they are the `real ip',
> making evil people able to circumvent any protections based on IPs.
Is that even possible?
> You use return statements that will never get executed.
> You use ereg_* instead of preg_*.
Ereg is slow and not the prefered way anymore I would say (although it
not an official standard and there is code in PEAR that uses ereg)
Regards,
Lukas