I'm curious about if people still use implicit var...
# cfml-general
g
I'm curious about if people still use implicit variable and / or implicit query loop scopes ?
d
Could you elaborate further? Perhaps with a few examples?
g
Starting with implicit variables in a CFM, would you <cfset temp = "" /> or <cfset VARIABLES.temp = "" /> and then access via <cfif temp> or <cfif VARIABLES.temp>
Secondly, if looping over a query that say has a field called "record_id" would you <cfloop query="qry"> <cfif qry.record_id> or <cfif record_id> </cfloop>
b
In general I always prefer to use variables with explicit scope, especially when looping over a query - I've been bitten too many times by duplicate variable names. 'variables' is too cumbersome though and I prefer to use 'local' scope instead.
☝🏻 1
g
Is local available in a template?
Cfm
a
the
local
scope that's built into functions is not available in
cfm
files. However if you do
local.foo
in a cfm file it'll work just fine but really it is
variables.local.foo
(on ACF that is, Lucee I think is different)
a
@Gareth: https://helpx.adobe.com/uk/coldfusion/developing-applications/the-cfml-programming-language/using-coldfusion-variables/about-scopes.html. Required baseline knowledge before deciding when one should / should not explicitly scope things. For my own code, I "never" explicitly scope the "nearest" scope (so: local in functions, variables in .cfm files). Anything else I generally do scope, as it's important for the sake of clarity to make sure it's clear the variable is not in the "nearest" scope. For my day job we have coding guidelines that say "always scope".
💯 2
👍 1
d
(I'm 100% the "For my own code..." statement)
a
I would add to this though, that "for my own code" all my methods and classes are as on-point as possible - paying particular heed to the Single Responsibility Principle - so are all pretty small so there's as little chance as possible to get caught out by the cognitive dissonance that might be created by having to keep too much code in one's head at a time, thus being benefited by actively scoping variables to keep them "distinct" from each other. If one has methods that are dozens of lines long, one might need all the help one can get keeping things straight in one's hed.
➕ 1
The codebase in my day job was originally written by a team that was unaware of concepts like the SRP, or other Clean Code notions, so we have methods that are 100s of lines long to contend with, and poss the verbosity around "always scope" helps us there. Plus also the codebase has "interesting" usage of the variables scope in CFCs (it's CFWheels... which brings its own quirks to the party). So it really does depend on the hand that one has been dealt as to how best to approach this stuff.
🎯 1
d
I generally prefer being explicit whenever possible (e.g. add semi-colon when not technically necessary), but it feels like scoping variables in a function to the "LOCAL" scope is just too overly verbose for most cases. There are times when it's certainly appropriate (or even needed), but I think it tends to make the code harder to digest. That said, it does certainly open you up to unexpected behavior because it can make you vulnerable to being exploited. Reference a variable that you expect to be in the LOCAL scope, but was never var scoped, it could lead to the value coming in from other public scopes, etc.
a
^^^ would likely be picked up by automated testing? Obvs requires one to actually have automated testing, that said.
a
scopes bleeding can lead to race conditions, but automation tests (unit / integration) don't tend to pick them up. Load tests may do. I find cflint is pretty good at finding them - you do get false positives but I'd rather have a few of those than not scanning the code at all.
👍 1
a
Yeah makes sense
g
I understand most scopes and have general standards for their use , it was more a question about potential use cases that I'm not using or haven't come across personally, mostly for some cfllint work I've been doing
https://github.com/cfmleditor/CFLint/tree/ImplicitScopeChecker still doing some internal testing, hope to make it available as a snapshot soon
Code has been modified for privacy
👍 1
a
I think any detection at all is good, so this is a win. Stretch goal would be for it to be a configurable rule though. (Dunno what linting systems are like in CFML, but I'm used to phpmd / phpcs as baselines for this sort of thing, and it's all configurable) What's Ortus's CFML Coding Guidelines say? I don't agree with it, but it's the closest CFML has as a standard.
g
if you're using .cflintrc files then this rule can be included or excluded
might have to do some work on local and this scopes, and then maybe rc, prc and event? ( for ortus ? )