Re: [PEPr] Comment on RFC::EvalForbiddance
| From: | Tobias Schlitt | Date: | Tue, 16 Aug 2005 13:05:53 +0000 |
| Subject: | Re: [PEPr] Comment on RFC::EvalForbiddance | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39405@lists.php.net to get a copy of this message | ||
Hi Alan Knowles!
On 08/16/05 14:53 you wrote:
> I'm not sure "banning it" is a good direction.
> eval (and preg_replace /e) usage should be strongly discouraged, however
> when used, files containing it should contain a Security summary giving
> the justification / explaination.
> There are a number of valid uses for it, but it does have to be used with
> great care...
I fully agree with the above points. But I think forbidding it completly
in the first place is the best way to go, so (especially new) developers
at first start searching for alternatives.
For the case the usage of eval() is not avoidable, we should introduce a
rule that people have to get their source validated from PEAR QA (or any
other institution in PEAR) before thay may release it.
> Perhaps a security policy document would be more useful.. - each package
> should have a @security tag, and list any potential issues that users
> should be aware of... (eg. like SQL injection etc.)
Making packages the way, that they don't get released with such issues
is the better way, I think.
Regards,
Toby
--
Tobias Schlitt - Zend Certified Engineer GPG Key: 0xA6529579
PEAR (PHP Extension and Application Repository) http://pear.php.net
Developer, Member of the PEAR Core QA Team & PEAR Website Team
Like to say "thank you"? - http://pear.php.net/wishlist.php/toby