[PEPr] Comment on RFC::EvalForbiddance
| From: | Joshua Eichorn | Date: | Tue, 16 Aug 2005 16:05:41 +0000 |
| Subject: | [PEPr] Comment on RFC::EvalForbiddance | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39422@lists.php.net to get a copy of this message | ||
Joshua Eichorn (http://pear.php.net/user/jeichorn) has commented on the proposal for
RFC::EvalForbiddance.
Comment:
There are a 2 major cases where eval can't be replaced.
Providing compatability between php5 and php4, (generally this is about
about not throwing warnings in php5)
Generating classes on the fly, wsdl stub classes or mock objects are what
I can think of off the top of my head.
The first use should be allowed as long as you follow a set of sane
rules.
The second should only be allowed if with an audit by two devs outside the
package before each major release.
Some sort of eval usage note would also be good to help auditing, either
an @security tag or just a file containing a list of all eval usage.
Proposal information:
http://pear.php.net/pepr/pepr-proposal-show.php?id=288
--
Sent by PEPr, the automatic proposal system at http://pear.php.net