Re: Play nice! Re: Savant/Flexy/Foo template engines

From: Date: Thu, 10 Jun 2004 09:59:08 +0000
Subject: Re: Play nice! Re: Savant/Flexy/Foo template engines
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-30376@lists.php.net to get a copy of this message
Tomas V.V.Cox wrote:
- By default I'd not let php code in templates if they are not compiled, is imho a security risk.
Just to throw in my $0.02 and also to kind of justify why different approaches to template engines can make sense: I think it's okay to use plain PHP in templates *if* the templates are just the GUI for a standard application, meaning the only people who touch the templates are developers or designers working directly with the developers. This would be a use-case where something like Savant could come into play. If you have templates that are submitted by end-users, like in a content management system, then yes, plain PHP code would pose a security risk. In this case, I'd prefer either a template engine using its own set of tags/language or even better a pure placeholder-based engine like IT, Sigma and the like. Saying PHP code in non-compiled templates is a security risk is a bit too generalized, IMHO. CU Markus

« previous php.pear.dev (#30376) next »