Re: How to overwrite PHP file analyzer with channel validator?

From: Date: Wed, 29 Oct 2008 16:23:21 +0000
Subject: Re: How to overwrite PHP file analyzer with channel validator?
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-50977@lists.php.net to get a copy of this message
Zitat von Brett Bieber <brett.bieber@gmail.com>:
On Wed, Oct 29, 2008 at 5:58 AM, Jan Schneider <jan@horde.org> wrote:
Here's a question for the PEAR installer gurus: is it possible to provide a channel validation package through <validatepackage> in channel.xml, that not only validates the package.xml but also intercepts the analyzing of PHP files, i.e. PEAR_PackageFile_v2_Validator::_analyzePhpFiles()? As far as I can see, a channel validator can only extend and replace PEAR_Validate, but I might be missing something.
I think you're correct. You can only alter the PEAR_Validate functionality - the files within packages are handled according to their respective file roles - but for PHP files, it appears that PEAR internally handles validation of these files. Is this only a problem at package time, or does the end user see errors when they install the package?
Only at package time.
As far as I can tell, _analyzePhpFiles() just determines if the classes/methods are prefixed with the package name, and if not, gives a warning at package validation time - which seems like a sane check.
Yes, and the rules for this class name check are exactly what I want to tweak.
A thought - could you build a custom file role for your PHP files? role='hordephp' and use <phpfile /> in the xml role to bypass the PEAR PHP file validation?
That might be possible, but I still want the other PHP file checks to run. And afaics, there are no validators for file roles either. Even if that was possible, I would probably end up duplicating most of the php role validator.
Per-channel file role validation rules seem like a nice feature though - have you thought through some of the details of this and if it would be feasible? Also if there are any possible security considerations?
There are no security issues, because the validation only happens during the packaging. I didn't have thought this through yet, since I wasn't sure if I simple missed something. Jan. -- Do you need professional PHP or Horde consulting? http://horde.org/consulting/

« previous php.pear.dev (#50977) next »