Make sure they really really trust the source of the input.

Comments

klausi’s picture

Issue summary: View changes
Status: Active » Closed (won't fix)

Coder 7.x is frozen now and will not receive updates. Coder 8.x-2.x can be used to check code for any Drupal version, Coder 8.x-2.x also supports the phpcbf command to automatically fix conding standard errors. Please check if this issue is still relevant and reopen against that version if necessary.

greggles’s picture

Version: 7.x-2.x-dev » 8.x-2.x-dev
Status: Closed (won't fix) » Active

It is still relevant. Thanks.

klausi’s picture

The /e modifier for preg_* functions is already covered in PregSecuritySnif with "Using the e flag in preg_*() is a possible security risk. For details see https://www.drupal.org/node/750148 ".

For eval() we could just add it to DiscouragedFunctionSniff?

greggles’s picture

Title: Look for eval or the /e modifier and warn people about implications » Look for eval and warn people about implications

Sounds great!

  • klausi committed 67a76dd on 8.x-2.x
    feat(DiscouragedFunctionsSniff): Add a warning to not use the PHP...
klausi’s picture

Status: Active » Fixed

Pushed that.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.