[PEPr] Comment on RFC::EvalForbiddance
| From: | Alan Knowles | Date: | Tue, 16 Aug 2005 12:53:26 +0000 |
| Subject: | [PEPr] Comment on RFC::EvalForbiddance | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39401@lists.php.net to get a copy of this message | ||
Alan Knowles (http://pear.php.net/user/alan_k) has commented on the proposal for
RFC::EvalForbiddance.
Comment:
I'm not sure "banning it" is a good direction.
eval (and preg_replace /e) usage should be strongly discouraged, however
when used, files containing it should contain a Security summary giving
the justification / explaination.
There are a number of valid uses for it, but it does have to be used with
great care...
Perhaps a security policy document would be more useful.. - each package
should have a @security tag, and list any potential issues that users
should be aware of... (eg. like SQL injection etc.)
Proposal information:
http://pear.php.net/pepr/pepr-proposal-show.php?id=288
--
Sent by PEPr, the automatic proposal system at http://pear.php.net