4 ms·
You may be drowning in the kool-aid. It is very easy to write tiny secure code in PHP without a framework. Of course if you're building a social network, then i
by RyanZAG 10y ago
You may be drowning in the kool-aid. It is very easy to write tiny secure code in PHP without a framework. Of course if you're building a social network, then it will run into some of those potential security issues. But for most of the small problems you're using PHP to solve, you really don't need to be a security expert as long as you're not piping user input directly to your database or OS.
It's kind of the point of the whole page - you don't need a massive general framework to solve your specific problem. Maybe read the whole thing instead of just skimming it.
- sametmax 10y agoNo it's not easy. You need to be sure you escape everything, setup a mecanism for allowed host, CSRF, anti click-hijacking and of course ensure your auth workflow is nicely designed. And that supposes that not only you know about it, but also how to implement it properly. Not to mention the time to code it, document it, test it and maintain it. Most custom PHP site I encounter are full of gigantic holes. And then other developpers comes in, and have to learn how to use your non standard code, that is unlikely to be half as well written, tested or documented than standard solutions. Of course custom code has also a cost, which means doing all that, even not very well, will take a toll on the budget, which you can't spend on other security aspects. All that while security is generally the last item on the budget list.
- pc86 10y agoI think RyanZAG was referring to solving one small problem with a PHP script. That does not necessitate a web page or any of the security mechanisms you suggest.
- sametmax 10y agoThere is no such things as a "general purpose" framework anyone would use for such a small script. This would make no sense.
- PolCPP 10y agoAlso, he mentions that company uses framework, won't scale and start ripping it apart to take unnecesary parts. You don't do that for a 50 line script
- RyanZAG 10y agoYou often do though: as in, if each independent problem was handled by a microservice PHP script, it would just be a 50 line script. But if you've built it on top of a huge framework then you can end up with all the separate parts stuck together in a massive project where you're not even using 75% of the framework.
- PolCPP 10y agoTheres a few things here. 1.- Massive project where you're not using 75% of the framework. Let's say i don't want the template engine and the ORM, the framework should let me pull them out. If i need them at some point i'll pull them in. But i know that when i do, these things will be maintained and working. And this is where a good framework shines. No need to deal with a dependency hell, and you should be able to pull out easily what you don't need. Edit: If you're just using a 25% of a framework and have no prospects on using it maybe you should look for something smaller 2.- Separate parts stuck on a massive project Thats not the framework fault but yours. You should write the parts of the application in a way that you can reuse them in another project, using the same framework or in a similar framework with as few changes as possible. And also its part of your work knowing a bit on how the framework works under the hood. The same way an android dev not only needs to know how 'generic' java works, but how android's java vm works. 3.- Those microservices may not follow a standard. While frameworks allow you to write bad code, they kind of force you to follow some standards which reduce bad code and let other developers take on the project easily. On the other side, a well developed microservice based project is usually better than an equivalent one that was based up on a framework. But it takes more time/work and has more risks (specially in php).
- RyanZAG 10y agoIf its under 50 lines of code for some simple processing, I don't think another developer who comes in would have much trouble. Of course if that 50 lines of code is now 250 because it tries to get around a framework, then instead of finding a PHP developer to help out on the code, you now need a $framework developer. Basically, don't use a framework unless you really do need all the features it gives you. Don't just pick a framework and try to cram your code into it for the sole purpose of using a framework.
- spriggan3 10y ago> If its under 50 lines of code for some simple processing It doesn't matter how much lines you write. It has nothing to do with the number of lines but the functionalities and how many developers review that piece of code. Furthermore more a third party codebase is usually the code you don't have to test. You keep on talking about frameworks like it's a bad thing, but all frameworks are not equal in size nor features.
- kijin 10y agoYou still don't need a framework for that. Just use composer to install a bunch of well-tested, feature-rich, but fully independent packages. Start your script with include 'vendor/autoload.php'; and add 50 lines of your own code.
- stephenr 10y agoDon't forget to understand how/why/what those other packages do. Including a package based on the contents of its packagist description alone is basically like reading the ingredients for a pizza and then eating a bag of flour.
- kijin 10y agoIt's the same with frameworks. "Modern PHP" frameworks usually include a ton of composer packages.
- cowsandmilk 10y ago> And then other developpers comes in, and have to learn how to use your non standard code If you use a framework, new developers coming in often have to learn how to use it as well. I've never hired a developer who didn't know how to use PDO prepared queries, which are the standard in my code base. Built into the language, escapes no matter what database you use, etc. Good developers know how to write secure PHP code without a framework. They don't necessarily know how to use a random framework. Bad developers will at some point take variables from a $_POST/GET array and use them unwisely regardless of whether you have a framework.
- spriggan3 10y ago> It is very easy to write tiny secure code in PHP without a framework Actually it isn't, like at all. A open source framework will always be more secure than the code you "easily write", because a larger pool developers can review,audit,test and fix that code.
- RyanZAG 10y agoSure, the framework code will be more secure. But you still need to solve your problem and your framework isn't going to do it. So you have to write code. The code you do write is going to be more secure if you know what's going on. If it's on top of a billion line framework, you might accidentally break the security without even realizing it. No legions of framework developers reviewed, audited, tested or fixed your actual code.