Re: Evil e
boots <[email protected]> Thu, 8 Feb 2007 16:55:57 -0800 (PST)
| Newsgroups | gmane.comp.php.smarty.devel |
|---|---|
| Message-ID | <[email protected]> |
--- messju mohr <[email protected]> wrote: > On Thu, Feb 08, 2007 at 06:01:08PM +0100, Danilo Buerger wrote: > > I suggest applying the following patch to prevent 2 problems: > > a) Using the "e" pattern modifier is nearly as evil as programming cobol > > /e is evil, so is create_function(). if we want to clean this up, we > should add a method like replace_special_blocks() to Smarty_Compiler > and use this as callback together with preg_replace_callback(). This is indeed better for this circumstance but I disagree with the hypothesis. Eval is useful, though of course it can be dangerous and it does have the *potential* for danger here. > > b) If one of the delimiters is set to "'" it could get really ugly > > good point. if there are more places in the compiler that cause > problems we should also add to the manual of > $smarty->(left|right)_delimiter that certain strings are not > supported. Agreed. And we should maybe make the compiler forbid them as well. Or we can create getters/setters for the delims and enforce it there. > > Index: Smarty_Compiler.class.php > > =================================================================== > > RCS file: /repository/smarty/libs/Smarty_Compiler.class.php,v > > retrieving revision 1.386 > > diff -r1.386 Smarty_Compiler.class.php > > 268,273c270,279 > > < $source_content = preg_replace($search.'e', "'" > > < . > > $this->_quote_replace($this->left_delimiter) . 'php' > > < . "' . str_repeat(\"\n\", > > substr_count('\\0', \"\n\")) .'" > > < . > > $this->_quote_replace($this->right_delimiter) > > < . "'" > > < , $source_content); > > --- > > > $source_content = preg_replace_callback( > > > $search, > > > create_function( > > > '$matches', > > > 'return \'' . addslashes($this->left_delimiter) . 'php' > > > . '\' . str_repeat("\n", substr_count($matches[0], > > "\n")) . \'' > > > . addslashes($this->right_delimiter) . '\';' > > > ), > > > $source_content > > > ); ____________________________________________________________________________________ Need Mail bonding? Go to the Yahoo! Mail Q&A for great tips from Yahoo! Answers users. http://answers.yahoo.com/dir/?link=list&sid=396546091 -- Smarty Development Mailing List (http://smarty.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php