Re: [PEPr] Comment on RFC::EvalForbiddance
| From: | Martin Jansen | Date: | Tue, 16 Aug 2005 15:04:19 +0000 |
| Subject: | Re: [PEPr] Comment on RFC::EvalForbiddance | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39416@lists.php.net to get a copy of this message | ||
On Tue Aug 16, 2005 at 02:1801PM -0000, Alexey Borzov wrote:
> Of the several packages I maintain two make extensive use of eval() /
> preg_replace('/.../e'). So I am -1 to forbidding the eval() usage.
Well, if you look over the proposal again you'll notice that there is a
section entitled "Exceptions". This means that as long as you can justify
your usage of eval() with _good_ reasons and as long as you take special
care that nothing maliciously creeps in there, using eval() is fine.
> While I do understand that in morons' packages eval() may create a huge
> security threat,
I wouldn't call Stig and Daniel morons, but you are of course free to call
people whatever you want. :-)
- Martin