I'm using PHP as a template engine in an MVC-style application. However, we now have the need for the templates to be edited via the web-front end. Is there a way to make this safe and secure, so a user who has the rights to edit a template then doesn't have the ability to run dangerous code on the server? Or, should using PHP as a template engine be abandoned, and use one of the many other templating engines, such as Smarty?
0
votes
Nope. You'll need to choose a "real" templating language that is designed for this purpose. But most of those still allow "dangerous" things to happen. e.g. cross-site scripting is a huge front-end problem - it can't be remediated at the controller-level as you don't know where in the page architecture the view is going to inject the data. It sounds like your real issue is the lack of a suitable review and approval stage in your publishing process pipeline.
- Cheekysoft
2 Answers
0
votes
I highly recommend twig. Twig is very nice in that it is very modular an extensible, so you will end up with a template engine that's as simple and as complicated as you wish.
It is also very fast with caching turned on in production. It is also very safe in that it cleans and filters what is displayed to the user, so no arbitary PHP code can be executed by the person editing the template.
0
votes
If you really like to make it secure: don't use PHP for your templates. There is no clean way to treat those templates different from your application code.
What you are looking for in fact is a template engine like Smarty or FLOW3's FLUID (I prefer the latter) as they have been built for exactly this demand (amongst others).