Re: XML/Parser.php stuff
| From: | (Stig Sæther Bakken) | Date: | Sun, 06 May 2001 08:21:42 +0000 |
| Subject: | Re: XML/Parser.php stuff | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-348@lists.php.net to get a copy of this message | ||
["Tomas V.V.Cox" <cox@idecnet.com>]
> Hi,
>
> Using the Parser I found some things that I think should be corrected:
>
> 1) Error handling: As the error objects returned by the class are of
> type XML_Parser_Error, and there isn't a XML_Parser::isError() I can't
> do manual checking for errors :-?
Huh? You're supposed to use PEAR::isError(). No use in calling some
method in a value before you know what type or class it has. :-)
> 2) funcStartHandler and funcEndHandler: Here is a security risk IMHO.
> For example if I don't use folding and build an xml file so:
>
> <root>
> <parse>foo</parse>
> </root>
>
> The class will call the parse() method (also whichever method from this
> class or parents) and do a good mess :) My proposal to fix it, is for
> example to append a safe prefix:
>
> function funcStartHandler($xp, $elem, $attribs) {
> if (method_exists($this, 'xml_' . $elem)) {
> call_user_method('xml_' . $elem, $this, $xp, $elem, &$attribs);
> }
> }
> (also in funcEndHandler)
Good point. To avoid the same problem with the xml_* functions, I'll
add a "xmltag_" prefix and put a note about it in the 4.0.6 release
notes.
> 3) folding: How can I set the folding? It should be a setFoo to do that,
> no? (umm.. i see that this in the TODO, ok leave here anyway :)
I'll fix the constructor so you can set it there plus add a setOption
method.
- Stig
--
Stig Sæther Bakken <ssb@fast.no>
Fast Search & Transfer ASA, Trondheim, Norway