Re: Re: [PEPr] Comment on RFC::EvalForbiddance

From: Date: Tue, 16 Aug 2005 19:32:24 +0000
Subject: Re: Re: [PEPr] Comment on RFC::EvalForbiddance
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-39434@lists.php.net to get a copy of this message
Hi, Martin Jansen wrote:
Of the several packages I maintain two make extensive use of eval() / preg_replace('/.../e'). So I am -1 to forbidding the eval() usage.
Well, if you look over the proposal again you'll notice that there is a section entitled "Exceptions". This means that as long as you can justify your usage of eval() with _good_ reasons and as long as you take special care that nothing maliciously creeps in there, using eval() is fine.
Yes, I understood this section. But consider this: without this proposal, if you don't like the way eval() is used in my packages you can still open the bug report, start the thread in pear-dev, etc. We also already have the QA team that theoretically should review the packages for security threats like these. What exactly prevents these guys from reviewing packages right now? So the only thing you gain from these proposal is a lot of noise from package developers who are using eval() and would like to continue doing so.
While I do understand that in morons' packages eval() may create a huge security threat,
I wouldn't call Stig and Daniel morons, but you are of course free to call people whatever you want. :-)
OK, using the word "moron" wasn't the brightest idea on my part, sorry. Indeed, these guys didn't have resources to even review the package they inherited for possible security issues. And now you think that people of their qualification will review package belonging to someone else?.. This only strengthens my "lack of time" argument that you conveniently removed from the quote. ;)

« previous php.pear.dev (#39434) next »