Re: Re: [PEPr] Comment on RFC::EvalForbiddance
| From: | Clay Loveless | Date: | Tue, 16 Aug 2005 15:39:38 +0000 |
| Subject: | Re: Re: [PEPr] Comment on RFC::EvalForbiddance | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39418@lists.php.net to get a copy of this message | ||
Pierre-Alain Joye (pierre@dotgeek.org) wrote:
> This is the perfect example of a bad usage of eval. Not having
> serious security issue (if $obj is defined and used only in
> this scope), but still horrible. And eval raises notices too...
>
> A tip, class_exists('myclass') && $obj instanceof myclass,
> but this is not the topic, that fits more in php-general.
Pierre,
Apparently you haven't done any coding that attempts to avoid "is_a"
deprecation warnings in PHP5 and the parse errors that "instanceof" usage
causes in PHP4.
There's been some discussion of this usage of eval() over the past couple of
months [1], and I don't recall you telling any of those people that "their
safe" was on php-general [2].
Please don't make our disagreements of late personal, Pierre. And even if
you must make them personal, a personal attack on me is still no excuse for
spreading FUD about eval() usage in regard to PHP4/PHP5 code compatibility.
-Clay
[1] http://blog.joshuaeichorn.com/archives/2005/08/01/using-eval-in-php/
[2] http://news.php.net/php.pear.core/3591
--
Killersoft.com