PHP - Framework, ORM, Encapsulation
Programming languages / environments aside, are there many developers who use the framework in PHP, ORM and still enforce encapsulation for DAL / BLL? I run a team of several developers and I find that most frameworks require me to review the code on a daily basis because my developers use the built-in ORM.
I am currently using a tool to create classes and CRUD on my own, with scope to write them additional requests / functions. However, they create vulnerabilities by not performing proper data resolution checks or by allowing manipulation of key fields on a form.
Any suggestions other than the new team and new language (I've seen Python / Ruby structures have the same problems).
Dropping a team will never be possible: improve it!
- Organize safety seminars so that they know more about these issues.
- Imagine (or even better: ask them to enter) lines of code to better manage these issues ( safe Hungarian notation or using prepared statements are two examples)
- Pay attention to short sentences in code reviews - don't blame them for ignoring security, just show the problematic fragments you have identified and explain that security is very important to [pick one: this project / client / your company's reputation / you personally]
- Have them conduct the security audit on their own or their peer code. Let them know how easy it is to exploit such security flaws.
- Find other tools / frameworks that better support your security model. But beware: this option is very expensive! Your programmers will have to maintain the code in the old structure and learn the new one (in the worst case: they will need to learn the new language along with the new environment).
But this is mostly a problem that you have to tackle with your developers. If you declare war on them, you will surely lose (regardless of the outcome for the developers).
a source to share
It seems to me that you want to improve your coding culture. Check out the Extreme Programming Rules . Perhaps you can take a few tricks.
Basically, I get the impression that there is very little communication between the developers and you. I could just read it in it, but to me it sounds like the developers are locked in the basement and you sit somewhere else and get frustrated over them. Change that thinking. You are part of the team.
If your developers are unaware of the vulnerabilities they are injecting into code, consider weekly code reviews. Let the developers talk about the code they wrote. Let them learn from each other. Make the code collectively owned. Strengthening learning and constructive criticism.
Remember that I am not on the team.
a source to share
Would I Recommend Nepthali ? It is not an ORM, but the framework is for security. I.E. all variables are encoded before exiting the screen; if not explicitly defined not too much.
It's also pretty lean, no ORM etc., so you can plug in any ORM you want. It's pretty good, actually.
a source to share
If you want to check if a user has access to a property, this is a different tier than the data access tier. But still there are frameworks where you can override the default loading functionality and insert your logic after / before loading.
The lightest framework I have ever worked is db.php ( http://dbphp.net , https://github.com/hazardland/db.php ). But this is the code-first object-rational cartographer. You have to define classes than databases. \ Tables will be created according to your classes.
Take a look at the \ db \ table :: load method. Each class has its own \ db \ table handler instance located in the database :: tables array. You can override table :: load or create separate handlers for tables derived from the \ db \ table class and place them in the database table ::.
The only problem is that the structure is not fully documented but has a very light intuitive code structure and samples.
Another option is to make a dal structure yourself, in order to make it complete and powerful, it will take up to 3-4 months.
a source to share