Re: How to overwrite PHP file analyzer with channel validator?
| From: | Brett Bieber | Date: | Wed, 29 Oct 2008 14:18:25 +0000 |
| Subject: | Re: How to overwrite PHP file analyzer with channel validator? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-50975@lists.php.net to get a copy of this message | ||
On Wed, Oct 29, 2008 at 5:58 AM, Jan Schneider <jan@horde.org> wrote:
> Here's a question for the PEAR installer gurus:
>
> is it possible to provide a channel validation package through
> <validatepackage> in channel.xml, that not only validates the package.xml
> but also intercepts the analyzing of PHP files, i.e.
> PEAR_PackageFile_v2_Validator::_analyzePhpFiles()? As far as I can see, a
> channel validator can only extend and replace PEAR_Validate, but I might be
> missing something.
I think you're correct. You can only alter the PEAR_Validate
functionality - the files within packages are handled according to
their respective file roles - but for PHP files, it appears that PEAR
internally handles validation of these files. Is this only a problem
at package time, or does the end user see errors when they install the
package?
As far as I can tell, _analyzePhpFiles() just determines if the
classes/methods are prefixed with the package name, and if not, gives
a warning at package validation time - which seems like a sane check.
A thought - could you build a custom file role for your PHP files?
role='hordephp' and use <phpfile /> in the xml role to bypass the PEAR
PHP file validation?
Per-channel file role validation rules seem like a nice feature though
- have you thought through some of the details of this and if it would
be feasible? Also if there are any possible security considerations?
--
Brett Bieber