Re: [PEPr] Comment on RFC::EvalForbiddance

From: Date: Tue, 16 Aug 2005 15:17:08 +0000
Subject: Re: [PEPr] Comment on RFC::EvalForbiddance
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-39417@lists.php.net to get a copy of this message
On 16 Aug 2005 14:06:11 -0000 clay@killersoft.com ("Clay Loveless") wrote: > > Clay Loveless (http://pear.php.net/user/clay) has commented on > the proposal for RFC::EvalForbiddance. > > Comment: > > This seems like a good idea in general, but there are cases where > eval is the only way to go -- such as this snippet to > simultaneously avoid is_a() deprecation notices in PHP5, and > parse errors in PHP4: > > $is_a = false; > $major_php_version = PHP_VERSION; > if (intval($major_php_version{0}) < 5) { > if (is_a($obj, 'some_class')) { > $is_a = true; > } > } else { > $is_a = eval("return ($obj instanceof Some_Class) ? true : > false;"); } This is the perfect example of a bad usage of eval. Not having serious security issue (if $obj is defined and used only in this scope), but still horrible. And eval raises notices too... A tip, class_exists('myclass') && $obj instanceof myclass, but this is not the topic, that fits more in php-general. --Pierre

« previous php.pear.dev (#39417) next »