[PEPr] Comment on RFC::EvalForbiddance

From: Date: Tue, 16 Aug 2005 16:05:41 +0000
Subject: [PEPr] Comment on RFC::EvalForbiddance
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-39422@lists.php.net to get a copy of this message
Joshua Eichorn (http://pear.php.net/user/jeichorn) has commented on the proposal for RFC::EvalForbiddance. Comment: There are a 2 major cases where eval can't be replaced. Providing compatability between php5 and php4, (generally this is about about not throwing warnings in php5) Generating classes on the fly, wsdl stub classes or mock objects are what I can think of off the top of my head. The first use should be allowed as long as you follow a set of sane rules. The second should only be allowed if with an audit by two devs outside the package before each major release. Some sort of eval usage note would also be good to help auditing, either an @security tag or just a file containing a list of all eval usage. Proposal information: http://pear.php.net/pepr/pepr-proposal-show.php?id=288 -- Sent by PEPr, the automatic proposal system at http://pear.php.net

« previous php.pear.dev (#39422) next »