XML/Parser.php stuff
| From: | Tomas V.V.Cox | Date: | Fri, 04 May 2001 13:48:49 +0000 |
| Subject: | XML/Parser.php stuff | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-345@lists.php.net to get a copy of this message | ||
Hi,
Using the Parser I found some things that I think should be corrected:
1) Error handling: As the error objects returned by the class are of
type XML_Parser_Error, and there isn't a XML_Parser::isError() I can't
do manual checking for errors :-?
2) funcStartHandler and funcEndHandler: Here is a security risk IMHO.
For example if I don't use folding and build an xml file so:
<root>
<parse>foo</parse>
</root>
The class will call the parse() method (also whichever method from this
class or parents) and do a good mess :) My proposal to fix it, is for
example to append a safe prefix:
function funcStartHandler($xp, $elem, $attribs) {
if (method_exists($this, 'xml_' . $elem)) {
call_user_method('xml_' . $elem, $this, $xp, $elem, &$attribs);
}
}
(also in funcEndHandler)
3) folding: How can I set the folding? It should be a setFoo to do that,
no? (umm.. i see that this in the TODO, ok leave here anyway :)
Tomas V.V.Cox