4 ms·
> Truthiness (e.g. 0 == false, '0' == true, 'false' == true, etc.) makes it easier to introduce bugs. Use === instead; except for cryptography, where you want
by CiPHPerCoder 9y ago
> Truthiness (e.g. 0 == false, '0' == true, 'false' == true, etc.) makes it easier to introduce bugs.
Use === instead; except for cryptography, where you want hash_equals().
> There's a lot of discipline/linting still required in PHP, whereas other languages won't even compile if you do something risky.
And/or just use scalar type declarations: https://3v4l.org/SJKe1 https://3v4l.org/SJKe1
- bpicolo 9y agoScalar type declarations don't help detect usage of undefined variables, as an example. Phan is the only tool I've found that does, but it's a very heavyweight thing, given how necessary it is to prevent undefined variable exceptions.
- CiPHPerCoder 9y agoThat's a separate concern from truthiness. And if you aren't using nullable types (a 7.1+ feature), passing NULL gives you a TypeError. :)
- muglug 9y agoI wrote a similar tool that's slightly less heavyweight (doesn't rely on a separate extension): https://getpsalm.org/ https://getpsalm.org/
- CiPHPerCoder 9y agoYes, Psalm is great. We use it in a lot of our projects, and in the future will be using it in all of them. We absolutely love it. (It's on my "to blog about" queue.)
- bpicolo 9y agoI'm going to be trying it out. Thanks. The more lints the better when dealing with legacy monoliths!
- smt88 9y agoI agree that there are safe (or safer) ways to do things in PHP, but in business settings, it's often hard to enforce such things. "Discipline" is very hard to maintain consistently across people with different backgrounds. I've actually gone as far as rejecting commits that failed the linter and style checker, but that only works for code bases I have control over. It doesn't apply to the libs. I now prefer languages where the entire ecosystem is passing strict compilation requirements.