4 ms·
"The very existence of PHP is a contradiction" Uhm no for me coming from a C background I love PHP since its basically C with a lot of the boring/repetitive st
by throwaway1974 10y ago
"The very existence of PHP is a contradiction"
Uhm no for me coming from a C background I love PHP since its basically C with a lot of the boring/repetitive stuff abstracted away
Good PHP code exists, it only got a bad name due to "web developers" with no formal programming education stumbling across PHP and going "aha this can generate my html etc" and then proceeding to make a pile of mistakes.
PHP is a hammer, blaming the hammer is silly when the person using it might now know how to swing it safely.
- jlis 10y agothanks!
- roblabla 10y agoPHP (the interpreter) used to be filled with bugs, design flaws and incoherences. It got better lately, but IMO it still caries a huge mess of legacy stuff that shouldn't even exist (mysql_real_escape_string anyone?) In this case, both the hammer and the hammer's user can be blamed.
- Shanea93 10y agoPHP7 has removed a lot of the old cruft and made some small improvements to PHP's idiomatic syntax. One great example is the removal of the mysql_real_escape_string function. http://php.net/manual/en/function.mysql-real-escape-string.php http://php.net/manual/en/function.mysql-real-escape-string.p... Another is finally giving us a null coalescing operator, which is a solution for a constant pain point in dealing with raw PHP POST and GET parameters. The full "new features" list of PHP7: http://php.net/manual/en/migration70.new-features.php http://php.net/manual/en/migration70.new-features.php The change log of PHP7+: http://php.net/ChangeLog-7.php http://php.net/ChangeLog-7.php
- iopq 10y agoThey removed mysql_real_escape_string function so that you can use mysqli_real_escape_string http://php.net/manual/en/mysqli.real-escape-string.php http://php.net/manual/en/mysqli.real-escape-string.php
- greyman 10y agoNo, you use PDO::quote().
- CiPHPerCoder 10y agoNo, you use $pdo->prepare("SELECT id FROM foo WHERE bar = ? AND baz = ?") ->execute([$baz, $qux]); ...while taking care to set PDO::ATTR_MODE to PDO::ERRMODE_EXCEPTION and PDO::ATTR_EMULATE_PREPARES to false when your PDO object is initialized. https://github.com/paragonie/airship/blob/8b7edde11b5b57fcb4b46024ca2227fd3cd4fc28/src/Engine/Database.php#L40-L47 https://github.com/paragonie/airship/blob/8b7edde11b5b57fcb4... See also: http://stackoverflow.com/a/12118602/2224584 http://stackoverflow.com/a/12118602/2224584
- roblabla 10y agoThis is the problem I have with PHP. 15 ways to do something seemingly simple, and only one obscure way is correct (What's PDO::ATTR_MODE ?) And why does PDO try to emulate prepares ?
- stephenr 10y agoThat was 4 ways. The documentation identify what the options do.
- stephenr 10y agoNamed parameters are much simpler to use IMO.
- CiPHPerCoder 10y agoSimpler? No. Easier? Yes.
- spriggan3 10y ago> Good PHP code exists, it only got a bad name due to "web developers" with no formal programming education stumbling across PHP and going "aha this can generate my html etc" and then proceeding to make a pile of mistakes. It got a bad name due to the weird nature of PHP which is still a template engine , no matter how much features you had on top. It's like developing webapps in pure HAML, Jinja or Handlebars. PHP also has a lot of bad design language wise, due to the incompetence of its creator and early maintainers when it comes to language design.
- throwaway1974 10y agoPHP "can be" used as a templating engine, but its not the right way to do it nor do you have to use it in that manner. The correct way is to use Twig for your templates PHP is alot more than a "templating engine" if thats all you think of it then that is your choice
- TeMPOraL 10y agoTemplate engines are one of the more ridiculous inventions on the web, if you think of it. Doubly so if you have them in PHP, which is a perfectly good template engine - sure the syntax could be better, but the popular templating engines are even worse at any but most trivial tasks. They all start as an attempt to remove the possibility of writing meaningful code in them[0], and then grow cruft until they become Turing-complete due to the needs. The more stupid thing about them, which transcends PHP and touches all other programming languages, is the very idea of assembling HTML piecemal from unstructured text. HTML is a textual representation of a tree, and should always be constructed as such - and not by gluing strings together. It's kind of the same problem as with SQL injections, which would not be possible in the first place if people weren't gluing them together from strings. I'll probably get flamed for saying that, but really - many of the popular tools on the web are broken on a fundamental, conceptual level. [0] - because of a misunderstanding of the "don't write logic in your views" principle; sure, don't write business logic in your views, but that doesn't mean you don't need, or shouldn't use, a real programming language in your views.
- 10y ago
- mseebach 10y agoPHP is pretty objectively bad. For every thing PHP does decently well, something else does it better. Except for this one weird trick: PHP absolutely bulls-eye nothing-but-net nailed deployability before deployability was even a word. In 2000, you could download an installer that set up Apache, MySQL and PHP on your Windows box (and it worked, first time and every time), you could fire up Notepad and 15 seconds later look at "Hello World" in your browser. Then you could upload that PHP file to a web hotel at $10/month and the world could see that same Hello World perhaps 10 minutes after that. Heroku + Ruby on Rails gets close[1], but it took them nearly 10 years to catch up. That's why PHP is so popular. 1: in zero-to-one deployability for a new user -- the full development and deployability experience just a tiny bit up the learning curve is orders of magnitude better.
- spoiler 10y agoFWWIW Ruby is my favourite language, but it's nowhere near being as beginner-friendly for web development as PHP. This is mostly because PHP was designed as an "embedded" language from the grounds up, and by the fact it's so widely supported by hosting providers. Most hosting providers have no support for Rails (or general rack-based applications); most that do, offer patchy support, though. Furthermore, I remember a few years back, Ruby was a hassle to set up, especially on Windows.
- codedokode 10y agoThere are more popular and worse languages, for example Javascript: - no classes (so people end up emulating them: Backbone has methods to emulate class declaration and class inheritance) - no type hinting. You cannot specify function argument type or return type. It makes code harder to read and to maintain. - too forgiving. You can divide by zero or mistype a property name and get no error. You can add arrays to strings. It makes bugs harder to find. - no coding standard. Everyone uses whatever style they like - no single modules standard - no syntax for asynchronous operations - difficult to install XML library on Windows (you need to setup a Visual Studio to compile binary modules) > Heroku + Ruby on Rails gets close[1], but it took them nearly 10 years to catch up. You have to learn Linux and command line to use Ruby. No wonder it is more difficult for a newbie. Deploying and running an application is more complicated in Ruby. Also with long-living applications it is easy to get a memory leak. But recently PHP started to depend more on CLI tools too (installing and using composer might be not easy for people who got used to GUI and don't understand concepts like "working directory").
- spoiler 10y ago> "web developers" with no formal programming education I know developers who couldn't afford a "formal programming education" or couldn't/didn't go for various reasons, and they'd blow most "formally educated" developers out of the water. I think the word "formal" is surplus here. > stumbling across PHP and going "aha this can generate my html etc" and then proceeding to make a pile of mistakes. This holds true for anything in life, really. Anyone who uses a tool which they don't understand will sooner or later make a mistake with that tool, and keep making mistakes. WARNING: The next might be anecdotal, so YMMV. I used to write a lot of code in PHP (and I am grateful, because it is partially responsible for introducing me to the world of programming), but I slowly moved away from as time passed. The main problems with PHP (apart from some interpreter issues/design decisions which I won't cover, because there's an abundant amount of that online already) are the fact that: 1) it probably has the lowest entry barrier, with near-instant gratification and 2) there is an insane amount of online tutorials, blog posts, courses and even "books" created by people who *think* they understand programming (and PHP), but actually don't. Web development is not any more trivial than system development, or any less complicated. This probably goes for any type of development. To be proficient in either, you need need to cover a very wide range of domains, but PHP resources makes you feel like web development is trivial and easy. Anyone who assumes web development is trivial doesn't really know shit about web development (excuse the language). tl;dr: I mostly agree with you that PHP's design decisions aren't the only problem bad PHP code exists, and that people who use PHP are largely to be blamed for their own mistakes.
- throwaway1974 10y agoOf course I did not want to generalize and stereotype Yes PHP makes it easy for ANYONE to stumble into scripting/programming But IMHO that is a good thing, the world needs more people getting into programming, if they make mistakes so be it, learning from mistakes is a good way of learning anything.
- anexprogrammer 10y agoComing from a C background I used to hate PHP as it's inconsistent and flaky to the point of schizophrenia. Same applies to library naming. It positively encourages bad design and inconsistency. C wasn't and didn't. Nearly all PHP I came across was the mess of some self-taught stumbling way beyond the point they should have been screaming for help, and going back to photoshopp. The docs don't exactly help here (may have changed, it's been a few years) as the apparently helpful comments on each feature aren't moderated in any way and are frequently unhelpful or plain wrong - but they're left to encourage the unwary. I don't disagree it's perfectly possible to produce decent code with a good coder, and good principles applied to the project. I've seen some very clean looking PHP, and OO classes. That's been because they know the problems of the language and have been careful around such areas, or tried to avoid them entirely. I've worked on a couple of PHP based projects where I couldn't say a word against it as they'd used it well from the start. We are where we are, but I would have been happier if the tool most often used by "web developers" stumbling in was a little more constrained and consistent about it.
- mikegerwitz 10y ago> coming from a C background I love PHP since its basically C with a lot of the boring/repetitive stuff abstracted away It has a C-style syntax, but similarities almost completely stop there. Especially in modern OO PHP.