Re: [PEPr] Comment on RFC::EvalForbiddance
| From: | Philippe Jausions | Date: | Tue, 16 Aug 2005 20:05:13 +0000 |
| Subject: | Re: [PEPr] Comment on RFC::EvalForbiddance | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39437@lists.php.net to get a copy of this message | ||
Ian Eure wrote:
On Tuesday 16 August 2005 12:22 pm, Travis Swicegood wrote:- preg_* vs. string functionsIn my opinion, fear of a function/method is what causes the problem. If there's nothing online but "don't use that!" discussions about a function, it's that much harder for someone new to PHP to figure out why they're doing what they're doing. If, instead, there's a repository of discussions about why and when they're appropriate, it'll help them understand why and when eval() (or any other method) should and shouldn't be used.I completely agree with you. I think it's dumb to simply forbid something (in most cases), since there are almost certainly valid uses for it if you're careful. Perhaps writing up a "best practices" section for CS would be a good idea. I don't think this should be a requirement like the rest of CS, but a repository of helpful approaches and techniques. It could contain info on: - eval() - register_globals and globals in general - Common patterns (factory, singleton, accept, etc) - Variable/method naming consistency - Single vs. double quotes - String concatenation vs. sprintf() - Error handling (Exceptions? PEAR_Error? ErrorStack?) - Internationalization approaches - magic_quotes / input validation
I'd be glad to write up some of these if there's interest. +1 on volunteering your time ;-)Of course some would simply be linked to existing PEAR manual sections (or 3rd party web sites), but it would be very good to have a "Best Practices" section easily accessible. -Philippe