Hi!
I’m sure you expert PHP programmers out there are aware of using "global" on a variable in a function so that the variable, previously defined elsewhere, will be accessible to that function. Hold that thought.
I noticed something very strange today. I have a script that I’ve been testing. It worked great on the root of my website. Then I tried running it from MODx via a snippet, which puts it in a different folder (and domain) on my site. I adjusted paths and other config items to prep it.
When trying it, I had errors in a database call. I traced the problem, and found that the variables in a function were not "making it" to the function, despite the use of "global" in there - they came in empty (whereas they had worked perfectly in the other location). The database call barfed simply because the variables were empty, and MySQL threw up its hands, of course.
I had a number of theories, but nothing solid. All my includes seemed to be fine. I even thought of .htaccess weirdness, and tried a couple things regarding Rewrite and so on, no luck. Maybe something about hard-coded vs. relative paths somewhere??! Something about sessions??! Some kind of scope weirdness. I couldn’t find other examples of this online. I just don’t know enough PHP to say.
Very mystifying! Any ideas, explanations?
Thanks!!!!!
-
MODX Staff
- 10,725 Posts
Since the eval of the MODx snippet occurs within the scope of a function of the DocumentParser object, you must declare any variables expected from globals declared outside of the snippet explicitly, or reference them as $GLOBALS[’varname’]. The latter method is more portable and my preferred style (if I’m actually forced to rely on global variables, which I rarely ever do), as it clearly indicates the scope of the variable being used.
I stumbled upon this too some time ago, and it had me scratching my head for a while until I realized that the snippet code was already inside a function and so my global declaration was a layer too late.
Quote from: ZAP at Apr 12, 2007, 07:43 PM
I stumbled upon this too some time ago, and it had me scratching my head for a while until I realized that the snippet code was already inside a function and so my global declaration was a layer too late.
Zap,
That makes perfect sense! The light went on. It’s one of those puzzles, wrapped in an enigma, inside a quandary, et al.
Thanks, folks! Good thoughts.
I was able to jury-rig it to work; the question becomes, should I re-write the script to eliminate globals or leave it the way it is. I think I could do it by simply adding parameters to the function calls. (Any smarter ideas welcome). Globals form more of a security risk, right?
Best, S
If you can make it work with globals using Jason’s suggestion I think that’s probably OK. But if you can recode the script to pass the variables you need in function calls and therefore not need them as globals that would probably be better. You can also use a MODx plugin to set up your variables for various snippets if that’s helpful.
As I understand it, this is not a security issue (except to the extent that when you use a variable that has been declared elsewhere its contents may not always be what you expect in the local context, which can be confusing but it’s unlikely that a hacker could take advantage of unless you had some other problem that gave them an opening). When people talk about "Globals" as a security risk, I think they generally mean leaving register_globals on, which allows get, post, session, and cookie variables to be used globally without their specific array declaration (e.g., $_GET[’whatever’]). This is a huge risk, because it allows hackers to insert their own values in unexpected ways (usually via the query string in the URL) and find instances where variables haven’t been properly declared that they can replace with their own evil values.
So personally if the script is working with global variables I would leave it, unless it’s something you plan to use elsewhere or release to others or you just really want it to be done "right".
Zap,
You are the MAN!!!!!!!! Thanks again. I really appreciate it.
These concepts, and object-orientation and all that are a little confusing for a musician at first.

But I’m getting it, and let’s hope the little bug fixes I’ve been contributing will make up for my newbie programming skills.
Man, there are a lot of smart people around here!