Re: [PEPr] Comment on RFC::EvalForbiddance

From: Date: Tue, 16 Aug 2005 13:05:53 +0000
Subject: Re: [PEPr] Comment on RFC::EvalForbiddance
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-39405@lists.php.net to get a copy of this message
Hi Alan Knowles! On 08/16/05 14:53 you wrote: > I'm not sure "banning it" is a good direction. > eval (and preg_replace /e) usage should be strongly discouraged, however > when used, files containing it should contain a Security summary giving > the justification / explaination. > There are a number of valid uses for it, but it does have to be used with > great care... I fully agree with the above points. But I think forbidding it completly in the first place is the best way to go, so (especially new) developers at first start searching for alternatives. For the case the usage of eval() is not avoidable, we should introduce a rule that people have to get their source validated from PEAR QA (or any other institution in PEAR) before thay may release it. > Perhaps a security policy document would be more useful.. - each package > should have a @security tag, and list any potential issues that users > should be aware of... (eg. like SQL injection etc.) Making packages the way, that they don't get released with such issues is the better way, I think. Regards, Toby -- Tobias Schlitt - Zend Certified Engineer GPG Key: 0xA6529579 PEAR (PHP Extension and Application Repository) http://pear.php.net Developer, Member of the PEAR Core QA Team & PEAR Website Team Like to say "thank you"? - http://pear.php.net/wishlist.php/toby

« previous php.pear.dev (#39405) next »