Re: Warning: Call-time pass-by-reference in XML/Parser.php

From: Date: Mon, 17 Sep 2001 11:51:34 +0000
Subject: Re: Warning: Call-time pass-by-reference in XML/Parser.php
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-1968@lists.php.net to get a copy of this message
On Fri, 14 Sep 2001 01:32:30 +0200, cox@idecnet.com (Tomas V.V.Cox) wrote: > There is a security problem with this parsing mode. Until more and more > people continues using it, it's time to change the API. Basically the > change involves that the function name instead of being simply $elem it > will be replaced with "xmltag_$elem" (prefixing the "xmltag_" string). > Also we need to change the deprecated call_user_method() with > call_user_func() (making the class incompatible with php < 4.0.6 I > guess). I can't see that call_user_method() should be deprecated (in the manual)? And call_user_func() should be supported in all 4.x releases, also according to the manual. It was only the call-time pass-by-reference part (&$attribs) that was giving the warning. So I suggest that the '&' is removed, and then the user must specify it in the function declaration, if he/she feels that it is needed. > I know that we hate to break the API or make the class only usable with > the last avaible php version, but is there any other solution? If not > I'll do the changes in the next days. Why not just do it as quick as possible, before more people start using the current api? I have attached a suggestion that uses call_user_method() if a method exists or try to use call_user_func() otherwise. Function names are: 'xmltag'.$elem.'Start' and 'xmltag'.$elem.'End'. -- Tobias

Index: Parser.php =================================================================== RCS file: /repository/php4/pear/XML/Parser.php,v retrieving revision 1.16 diff -u -r1.16 Parser.php --- Parser.php 6 Jul 2001 01:32:04 -0000 1.16 +++ Parser.php 17 Sep 2001 11:32:31 -0000 @@ -248,12 +248,15 @@ // }}} // {{{ funcStartHandler() - function funcStartHandler($xp, $elem, $attribs) { + function funcStartHandler($xp, $elem, $attribs) + { + $funcName = 'xmltag'.$elem.'Start'; - if (method_exists($this, $elem)) { - call_user_method($elem, $this, $xp, $elem, &$attribs); + if (method_exists($this, $funcName)) { + call_user_method($funcName, $this, $xp, $elem, $attribs); + } elseif (function_exists($funcName)) { + call_user_func($funcName, $xp, $elem, $attribs); } - } // }}} @@ -261,9 +264,12 @@ function funcEndHandler($xp, $elem) { - $func = $elem . '_'; - if (method_exists($this, $func)) { - call_user_method($func, $this, $xp, $elem); + $funcName = 'xmltag'.$elem.'End'; + + if (method_exists($this, $funcName)) { + call_user_method($funcName, $this, $xp, $elem, $attribs); + } elseif (function_exists($funcName)) { + call_user_func($funcName, $xp, $elem, $attribs); } }
« previous php.pear.dev (#1968) next »