6 ms·
Once I wrote a little PHP application to manage a clan in a browser game. I used an MD5 hash as session id that I checked with if(session_id) When users st
by DoubleMalt 11y ago
Once I wrote a little PHP application to manage a clan in a browser game. I used an MD5 hash as session id that I checked with
if(session_id)
When users started reporting that their logins would sometimes not work at the first time, I found out that strings that start with zero are coerced to 0 and then interpreted as false.
Never used PHP for anything important since.
- rimantas 11y agoYeah, documentation is for pussies.
- imakesnowflakes 11y agoHere is one PHP core developer claiming that PHP documentation is wrong, even on fundamental things... http://www.reddit.com/r/lolphp/comments/2md8c0/new_safe_casting_function_rfc_casting_10_to/cm3dpdj http://www.reddit.com/r/lolphp/comments/2md8c0/new_safe_cast... Just saying....
- deleted 11y ago[deleted]
- sarciszewski 11y ago> I used an MD5 hash as session id > Never used PHP for anything important since. The problem here isn't PHP, the problem here is you.
- FeepingCreature 11y agoNah, the problem is PHP. See: http://blog.codinghorror.com/falling-into-the-pit-of-success/ http://blog.codinghorror.com/falling-into-the-pit-of-success... > When you write code in [PHP], you're always circling the pit of despair, just one misstep away from plunging to your doom.
- Navarr 11y agoI'd be willing to say this is true for any language in varying ways.
- BasDirks 11y agoAnd what is gained from doing so? We must remain critical.
- Silhouette 11y agoBut to widely varying degrees. This kind of problem is a direct consequence of having a relatively weak and dynamic type system (or other semantics that mean you might as well have). Plenty of people have warned about this kind of danger for a very long time. However, there seems to be a significant subset of the web development community that only has experience with languages like JS and PHP and to a lesser extent other dynamic languages like Ruby and Python, who simply fail to realise how many of these bugs should have been entirely prevented by using better tools by now. The usual counter seems to be something about unit tests, at which point anyone following the discussion who actually knows anything about type systems and the wider world of programming languages dies a little inside. It is entirely fair to criticise bad tools for being bad, particularly in specific ways and with clearly identified problems that can result as in this case. It's bad enough that we are stuck with JS for front-end web development these days, but there aren't many good arguments for using something as bad as PHP on the back-end in 2015.
- sarciszewski 11y agoNo, the problem is using a shitty function like MD5 for any practical purpose.
- return0 11y agoWhat did you use for the important stuff that was 100% predictable?
- merb 11y agozeroes and ones.
- ams6110 11y agoTo be fair, this kind of thing (maybe not exactly this, but type-coercion bugs) can happen in JavaScript, which is all the rage now for "important" stuff.
- wmil 11y agoIt can happen in a few languages, but PHP is notably more aggressive in trying to convert to int. Actually a common way to grief new websites is to try to register '0' as a username. `if (string)` is a common way to check for null, and '0' will often fail.
- bcruddy 11y agoYeah but javascript has 'use strict' whereas PHP decided that the easter egg "looks like you're using the wrong language!" was more important than actually allowing a 'use strict' to force === instead of ==.
- Silhouette 11y agoWhile that's true, JavaScript is still horribly error-prone because of this. The suggestion that JS would be a much better language if the == operator worked more like === in the first place is very reasonable.
- samspot 11y agoI don't think strict mode affects == vs. === Best bet is to use a linter to catch that.
- shuzchen 11y agoThis is levels worse than what Javascript does though. Most high-level languages have some sort of implicit coercion (even python lets you do truth tests on non-boolean values). The problem here is the programmer isn't confused about types at all. They're comparing two things of the same type: two strings! Nevertheless, given two strings PHP tries to coerce them into ints before carrying out the equality test. Yes, you will have coercion bugs in other languages if you're testing things of different types, but I don't know any other language where a equality test between two things of the same type are automatically coerced into another.
- tveita 11y agoThis does not appear to the case in PHP 5.6, even for most strings with '==' gotchas: <?php if ('0e24') echo 'true'; else echo 'false'; outputs: true As far as I know the only strings that fail an if check are "" and "0". (Which is still a pitfall, but not one you'd hit with an MD5 hash)