Re: On the use of eval() in XML_Query2XML
| From: | Alexey Borzov | Date: | Mon, 30 Oct 2006 12:23:50 +0000 |
| Subject: | Re: On the use of eval() in XML_Query2XML | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-44797@lists.php.net to get a copy of this message | ||
Hi,
Lukas Feiler wrote:
recently I stumbled across the EvalForbiddance RFCThe RFC was not accepted, it wasn't even called for votes. Therefore you aren't of course required to conform to it. It is not a good idea to abuse eval(), though, but if you aren't using it with user input and take measures to properly escape the strings, it is mostly OK.
(http://pear.php.net/pepr/pepr-proposal-show.php?id=288). It turns out that XML_Query2XML (I'm the lead developer for that package) uses eval() in a couple of places: