Re: Warning: Call-time pass-by-reference in XML/Parser.php
| From: | Tobias H . Michaelsen | Date: | Mon, 17 Sep 2001 11:51:34 +0000 |
| Subject: | Re: Warning: Call-time pass-by-reference in XML/Parser.php | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-1968@lists.php.net to get a copy of this message | ||
On Fri, 14 Sep 2001 01:32:30 +0200, cox@idecnet.com (Tomas V.V.Cox) wrote:
> There is a security problem with this parsing mode. Until more and more
> people continues using it, it's time to change the API. Basically the
> change involves that the function name instead of being simply $elem it
> will be replaced with "xmltag_$elem" (prefixing the "xmltag_" string).
> Also we need to change the deprecated call_user_method() with
> call_user_func() (making the class incompatible with php < 4.0.6 I
> guess).
I can't see that call_user_method() should be deprecated (in the manual)? And call_user_func()
should be supported in all 4.x releases, also according to the manual.
It was only the call-time pass-by-reference part (&$attribs) that was giving the warning. So I
suggest that the '&' is removed, and then the user must specify it in the
function declaration, if he/she feels that it is needed.
> I know that we hate to break the API or make the class only usable with
> the last avaible php version, but is there any other solution? If not
> I'll do the changes in the next days.
Why not just do it as quick as possible, before more people start using the current api?
I have attached a suggestion that uses call_user_method() if a method exists or try to use
call_user_func() otherwise.
Function names are: 'xmltag'.$elem.'Start' and
'xmltag'.$elem.'End'.
--
Tobias
Index: Parser.php =================================================================== RCS file: /repository/php4/pear/XML/Parser.php,v retrieving revision 1.16 diff -u -r1.16 Parser.php --- Parser.php 6 Jul 2001 01:32:04 -0000 1.16 +++ Parser.php 17 Sep 2001 11:32:31 -0000 @@ -248,12 +248,15 @@ // }}} // {{{ funcStartHandler() - function funcStartHandler($xp, $elem, $attribs) { + function funcStartHandler($xp, $elem, $attribs) + { + $funcName = 'xmltag'.$elem.'Start'; - if (method_exists($this, $elem)) { - call_user_method($elem, $this, $xp, $elem, &$attribs); + if (method_exists($this, $funcName)) { + call_user_method($funcName, $this, $xp, $elem, $attribs); + } elseif (function_exists($funcName)) { + call_user_func($funcName, $xp, $elem, $attribs); } - } // }}} @@ -261,9 +264,12 @@ function funcEndHandler($xp, $elem) { - $func = $elem . '_'; - if (method_exists($this, $func)) { - call_user_method($func, $this, $xp, $elem); + $funcName = 'xmltag'.$elem.'End'; + + if (method_exists($this, $funcName)) { + call_user_method($funcName, $this, $xp, $elem, $attribs); + } elseif (function_exists($funcName)) { + call_user_func($funcName, $xp, $elem, $attribs); } }
Index: Parser.php =================================================================== RCS file: /repository/php4/pear/XML/Parser.php,v retrieving revision 1.16 diff -u -r1.16 Parser.php --- Parser.php 6 Jul 2001 01:32:04 -0000 1.16 +++ Parser.php 17 Sep 2001 11:32:31 -0000 @@ -248,12 +248,15 @@ // }}} // {{{ funcStartHandler() - function funcStartHandler($xp, $elem, $attribs) { + function funcStartHandler($xp, $elem, $attribs) + { + $funcName = 'xmltag'.$elem.'Start'; - if (method_exists($this, $elem)) { - call_user_method($elem, $this, $xp, $elem, &$attribs); + if (method_exists($this, $funcName)) { + call_user_method($funcName, $this, $xp, $elem, $attribs); + } elseif (function_exists($funcName)) { + call_user_func($funcName, $xp, $elem, $attribs); } - } // }}} @@ -261,9 +264,12 @@ function funcEndHandler($xp, $elem) { - $func = $elem . '_'; - if (method_exists($this, $func)) { - call_user_method($func, $this, $xp, $elem); + $funcName = 'xmltag'.$elem.'End'; + + if (method_exists($this, $funcName)) { + call_user_method($funcName, $this, $xp, $elem, $attribs); + } elseif (function_exists($funcName)) { + call_user_func($funcName, $xp, $elem, $attribs); } }