Re: Play nice! Re: Savant/Flexy/Foo template engines
| From: | Markus Wolff | Date: | Thu, 10 Jun 2004 09:59:08 +0000 |
| Subject: | Re: Play nice! Re: Savant/Flexy/Foo template engines | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-30376@lists.php.net to get a copy of this message | ||
Tomas V.V.Cox wrote:
- By default I'd not let php code in templates if they are not compiled, is imho a security risk.Just to throw in my $0.02 and also to kind of justify why different approaches to template engines can make sense: I think it's okay to use plain PHP in templates *if* the templates are just the GUI for a standard application, meaning the only people who touch the templates are developers or designers working directly with the developers. This would be a use-case where something like Savant could come into play. If you have templates that are submitted by end-users, like in a content management system, then yes, plain PHP code would pose a security risk. In this case, I'd prefer either a template engine using its own set of tags/language or even better a pure placeholder-based engine like IT, Sigma and the like. Saying PHP code in non-compiled templates is a security risk is a bit too generalized, IMHO. CU Markus