Re: [PEPr] Comment on RFC::EvalForbiddance
| From: | Pierre-Alain Joye | Date: | Tue, 16 Aug 2005 15:17:08 +0000 |
| Subject: | Re: [PEPr] Comment on RFC::EvalForbiddance | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39417@lists.php.net to get a copy of this message | ||
On 16 Aug 2005 14:06:11 -0000
clay@killersoft.com ("Clay Loveless") wrote:
>
> Clay Loveless (http://pear.php.net/user/clay) has commented on
> the proposal for RFC::EvalForbiddance.
>
> Comment:
>
> This seems like a good idea in general, but there are cases where
> eval is the only way to go -- such as this snippet to
> simultaneously avoid is_a() deprecation notices in PHP5, and
> parse errors in PHP4:
>
> $is_a = false;
> $major_php_version = PHP_VERSION;
> if (intval($major_php_version{0}) < 5) {
> if (is_a($obj, 'some_class')) {
> $is_a = true;
> }
> } else {
> $is_a = eval("return ($obj instanceof Some_Class) ? true :
> false;"); }
This is the perfect example of a bad usage of eval. Not having
serious security issue (if $obj is defined and used only in
this scope), but still horrible. And eval raises notices too...
A tip, class_exists('myclass') && $obj instanceof myclass,
but this is not the topic, that fits more in php-general.
--Pierre