Active
Project:
Drupal core
Version:
main
Component:
other
Priority:
Normal
Category:
Plan
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
11 Jul 2022 at 10:11 UTC
Updated:
15 Jul 2022 at 02:47 UTC
Jump to comment: Most recent
Calling in_array() in loose mode, e.g. without $strict parameter set to TRUE is error prone and could lead to unexpected results. We , as a community , have already faced all sorts of issues related to such calls.
Example of such unexpected behaviour could be found here:
Use only strict mode when calling in_array(). Proposed in:
Drupal core always uses strict in_array() checks
- unfortunately no, Wim
SlevomatCodingStandard.Functions.StrictCall from slevomat/coding-standard, to check for strict mode (also was suggested here #3150614-53: Set SameSite on session cookies by @alexpott) to prevent future loose mode usageTBD, if needed.
Comments
Comment #2
rosk0Setting the title back
Comment #3
spokjeMe like!
There's already a sniff in the recently added-to-drupal/coder
slevomat/coding-standard:As described in the Sniff description, this is about more than "just"
in_array().Looking at the code here, it checks
in_array,array_search,base64_decodeandarray_keysfor the "TRUEness" of the$strictparameter.If I run this sniff on the current
10.0.x-devbranch, I get 535 PHPCS errors:Strict parameter missing in array_search() call.: 79 timesStrict parameter missing in in_array() call.: 455 timesStrict parameter missing in base64_decode() call.: 1 timeStrict parameter missing in in_keys() call.: 0 timesComment #4
spokjeTagging
Comment #5
spokjeUndoing component change :/
Comment #6
rosk0Updating description to include
SlevomatCodingStandard.Functions.StrictCallin Coder.