4 ms·
PHP supports lexical scope; it's just local to the current function. The actual problem is that PHP automatically initializes variables even on read—the same r
by eevee 13y ago
PHP supports lexical scope; it's just local to the current function.
The actual problem is that PHP automatically initializes variables even on read—the same reason all globals have to be manually "imported", even if they're only read from. Similar to the problem Python 3's `nonlocal` solves, except imagine a world where Python didn't have NameErrors and instead initialized every unrecognized name to None.
- anaphor 13y agoIs there much PHP code that relies on this "feature" or could they have changed it to actually search in the enclosing scope if something was read, and avoided the silly "use" keyword? I mean it's not like PHP has an actual spec, so they can change it whenever they feel like it as long as it doesn't break much.
- eevee 13y agoVariable declaration is pretty core to the language. Remember register_globals? That was only a problem because so much code relied on having undeclared variables act like empty strings. I suppose they could have made it work differently just for nested functions, but that's a major inconsistency, it's not clear how it would interact with globals, etc.
- stephenr 13y agoregister globals didn't "make undeclared variables act like empty strings". register globals imported request parameters from the query string and post body into the global variable scope. having undeclared variables "act like empty strings" is related to non-strict variable comparison (== vs ===) and either silencing errors, or not displaying/caring about them.
- eevee 13y agoregister_globals could not have existed without the legality of undeclared variables, and it could not have been a security issue without code that relied on using undefinedness as a default value.
- stephenr 13y agoundeclared variabels aren't legal, they cause errors. if your php is configured to ignore those errors thats on you. of course it could be a security issue without undefined variables coercing to an empty string in string context - it could allow request parameters to override defined variables.