Re: [PEPr] Comment on RFC::EvalForbiddance
| From: | Alan Knowles | Date: | Wed, 17 Aug 2005 03:37:25 +0000 |
| Subject: | Re: [PEPr] Comment on RFC::EvalForbiddance | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39441@lists.php.net to get a copy of this message | ||
My only concern with the 'forbidding' it rule is that it appears rather
dictatorial, and a little insulting to the intelligence of potential
contributors. Introducing it as 'eval()' usage in PEAR, and explaining
it clearly and why it's usage if considered bad, treats the
reader/visitor/potential contributor in a more respectful manner.
Good ole british politeness ;)
Regards
Alan
On Tue, 2005-08-16 at 15:05 +0200, Tobias Schlitt wrote:
> Hi Alan Knowles!
> On 08/16/05 14:53 you wrote:
>
> > I'm not sure "banning it" is a good direction.
>
> > eval (and preg_replace /e) usage should be strongly discouraged, however
> > when used, files containing it should contain a Security summary giving
> > the justification / explaination.
>
> > There are a number of valid uses for it, but it does have to be used with
> > great care...
>
> I fully agree with the above points. But I think forbidding it completly
> in the first place is the best way to go, so (especially new) developers
> at first start searching for alternatives.
>
> For the case the usage of eval() is not avoidable, we should introduce a
> rule that people have to get their source validated from PEAR QA (or any
> other institution in PEAR) before thay may release it.
>
> > Perhaps a security policy document would be more useful.. - each package
> > should have a @security tag, and list any potential issues that users
> > should be aware of... (eg. like SQL injection etc.)
>
> Making packages the way, that they don't get released with such issues
> is the better way, I think.
>
> Regards,
> Toby
> --
> Tobias Schlitt - Zend Certified Engineer GPG Key: 0xA6529579
> PEAR (PHP Extension and Application Repository)
> http://pear.php.net
> Developer, Member of the PEAR Core QA Team & PEAR Website Team
> Like to say "thank you"? -
> http://pear.php.net/wishlist.php/toby
>