Problem/Motivation

Calling in_array() in loose mode, e.g. without $strict parameter set to TRUE is error prone and could lead to unexpected results. We , as a community , have already faced all sorts of issues related to such calls.

Steps to reproduce

Example of such unexpected behaviour could be found here:

Proposed resolution

Use only strict mode when calling in_array(). Proposed in:

Remaining tasks

  1. Drupal core
    • grep code base to see the size of the issue
    • agree on approach - patch per component/module/sub-system?
  2. Introduce new code style rule in Coder, SlevomatCodingStandard.Functions.StrictCall from slevomat/coding-standard, to check for strict mode (also was suggested here #3150614-53: Set SameSite on session cookies by @alexpott) to prevent future loose mode usage

Release notes snippet

TBD, if needed.

Comments

RoSk0 created an issue. See original summary.

rosk0’s picture

Title: [META] » [META] Always call in_array() in strict mode

Setting the title back

spokje’s picture

Me like!

Remaining tasks

[snipped]
2. Introduce new code style rule in Coder to check for strict mode [snipped] to prevent future loose mode usage

There's already a sniff in the recently added-to-drupal/coder slevomat/coding-standard:

#### SlevomatCodingStandard.Functions.StrictCall

Some functions have `$strict` parameter. This sniff reports calls to these functions without the parameter or with `$strict = false`.

As described in the Sniff description, this is about more than "just" in_array().
Looking at the code here, it checks in_array, array_search, base64_decode and array_keys for the "TRUEness" of the $strict parameter.

If I run this sniff on the current 10.0.x-dev branch, I get 535 PHPCS errors:

Strict parameter missing in array_search() call.: 79 times
Strict parameter missing in in_array() call.: 455 times
Strict parameter missing in base64_decode() call.: 1 time
Strict parameter missing in in_keys() call.: 0 times

spokje’s picture

Component: other » cache system
Issue tags: +Coding standards

Tagging

spokje’s picture

Component: cache system » other

Undoing component change :/

rosk0’s picture

Issue summary: View changes

Updating description to include SlevomatCodingStandard.Functions.StrictCall in Coder.

Version: 9.5.x-dev » 10.1.x-dev

Drupal 9.5.0-beta2 and Drupal 10.0.0-beta2 were released on September 29, 2022, which means new developments and disruptive changes should now be targeted for the 10.1.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 10.1.x-dev » 11.x-dev

Drupal core is moving towards using a “main” branch. As an interim step, a new 11.x branch has been opened, as Drupal.org infrastructure cannot currently fully support a branch named main. New developments and disruptive changes should now be targeted for the 11.x branch, which currently accepts only minor-version allowed changes. For more information, see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 11.x-dev » main

Drupal core is now using the main branch as the primary development branch. New developments and disruptive changes should now be targeted to the main branch.

Read more in the announcement.