Re: [PEPr] Comment on RFC::EvalForbiddance

From: Date: Wed, 17 Aug 2005 03:37:25 +0000
Subject: Re: [PEPr] Comment on RFC::EvalForbiddance
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-39441@lists.php.net to get a copy of this message
My only concern with the 'forbidding' it rule is that it appears rather dictatorial, and a little insulting to the intelligence of potential contributors. Introducing it as 'eval()' usage in PEAR, and explaining it clearly and why it's usage if considered bad, treats the reader/visitor/potential contributor in a more respectful manner. Good ole british politeness ;) Regards Alan On Tue, 2005-08-16 at 15:05 +0200, Tobias Schlitt wrote: > Hi Alan Knowles! > On 08/16/05 14:53 you wrote: > > > I'm not sure "banning it" is a good direction. > > > eval (and preg_replace /e) usage should be strongly discouraged, however > > when used, files containing it should contain a Security summary giving > > the justification / explaination. > > > There are a number of valid uses for it, but it does have to be used with > > great care... > > I fully agree with the above points. But I think forbidding it completly > in the first place is the best way to go, so (especially new) developers > at first start searching for alternatives. > > For the case the usage of eval() is not avoidable, we should introduce a > rule that people have to get their source validated from PEAR QA (or any > other institution in PEAR) before thay may release it. > > > Perhaps a security policy document would be more useful.. - each package > > should have a @security tag, and list any potential issues that users > > should be aware of... (eg. like SQL injection etc.) > > Making packages the way, that they don't get released with such issues > is the better way, I think. > > Regards, > Toby > -- > Tobias Schlitt - Zend Certified Engineer GPG Key: 0xA6529579 > PEAR (PHP Extension and Application Repository) > http://pear.php.net > Developer, Member of the PEAR Core QA Team & PEAR Website Team > Like to say "thank you"? - > http://pear.php.net/wishlist.php/toby >

« previous php.pear.dev (#39441) next »