phpstan/phpstan-strict-rules

Repository files navigation

BuildLatest Stable VersionLicense

PHPStan focuses on finding bugs in your code. But in PHP there's a lot of leeway in how stuff can be written. This repository contains additional rules that revolve around strictly and strongly typed code with no loose casting for those who want additional safety in extremely defensive programming:

Configuration ParametersRule Description
booleansInConditionsRequire booleans in if, elseif, ternary operator, after !, and on both sides of && and ||.
booleansInLoopConditionsRequire booleans in while and do while loop conditions.
numericOperandsInArithmeticOperatorsRequire numeric operands or arrays in + and numeric operands in -/*///**/%.
numericOperandsInArithmeticOperatorsRequire numeric operand in $var++, $var--, ++$varand --$var.
strictFunctionCallsThese functions contain a $strict parameter for better type safety, it must be set to true:
* in_array (3rd parameter)
* array_search (3rd parameter)
* array_keys (3rd parameter; only if the 2nd parameter $search_value is provided)
* base64_decode (2nd parameter).
overwriteVariablesWithLoopVariables assigned in while loop condition and for loop initial assignment cannot be used after the loop.
overwriteVariablesWithLoopVariables set in foreach that's always looped thanks to non-empty arrays cannot be used after the loop.
switchConditionsMatchingTypeTypes in switch condition and case value must match. PHP compares them loosely by default and that can lead to unexpected results.
dynamicCallOnStaticMethodCheck that statically declared methods are called statically.
disallowedEmptyDisallow empty() - it's a very loose comparison (see manual), it's recommended to use more strict one.
disallowedShortTernaryDisallow short ternary operator (?:) - implies weak comparison, it's recommended to use null coalesce operator (??) or ternary operator with strict condition.
noVariableVariablesDisallow variable variables ($$foo, $this->$method() etc.).
overwriteVariablesWithLoopDisallow overwriting variables with foreach key and value variables.
checkAlwaysTrueInstanceof, checkAlwaysTrueCheckTypeFunctionCall, checkAlwaysTrueStrictComparisonAlways true instanceof, type-checking is_* functions and strict comparisons ===/!==. These checks can be turned off by setting checkAlwaysTrueInstanceof, checkAlwaysTrueCheckTypeFunctionCall and checkAlwaysTrueStrictComparison to false.
Correct case for referenced and called function names.
matchingInheritedMethodNamesCorrect case for inherited and implemented method names.
Contravariance for parameter types and covariance for return types in inherited methods (also known as Liskov substitution principle - LSP).
Check LSP even for static methods.
requireParentConstructorCallRequire calling parent constructor.
disallowedBacktickDisallow usage of backtick operator ($ls = `ls -la`).
closureUsesThisClosure should use $this directly instead of using $this variable indirectly.

Additional rules are coming in subsequent releases!

To use this extension, require it in Composer:

composer require --dev phpstan/phpstan-strict-rules

If you also install phpstan/extension-installer then you're all set!

Manual installation

If you don't want to use phpstan/extension-installer, include rules.neon in your project's PHPStan config:

includes:
    - vendor/phpstan/phpstan-strict-rules/rules.neon

You can disable rules using configuration parameters:

parameters:
	strictRules:
		disallowedLooseComparison: false
		booleansInConditions: false
		booleansInLoopConditions: false
		uselessCast: false
		requireParentConstructorCall: false
		disallowedBacktick: false
		disallowedEmpty: false
		disallowedImplicitArrayCreation: false
		disallowedShortTernary: false
		overwriteVariablesWithLoop: false
		closureUsesThis: false
		matchingInheritedMethodNames: false
		numericOperandsInArithmeticOperators: false
		strictFunctionCalls: false
		dynamicCallOnStaticMethod: false
		switchConditionsMatchingType: false
		noVariableVariables: false
		strictArrayFilter: false
		illegalConstructorMethodCall: false

Aside from introducing new custom rules, phpstan-strict-rules also change the default values of some configuration parameters that are present in PHPStan itself. These parameters are documented on phpstan.org.

If you don't want to start using all the available strict rules at once but only one or two, you can!

You can disable all rules from the included rules.neon with:

parameters:
	strictRules:
		allRules: false

Then you can re-enable individual rules with configuration parameters:

parameters:
	strictRules:
		allRules: false
		booleansInConditions: true

Even with strictRules.allRules set to false, part of this package is still in effect. That's because phpstan-strict-rules also change the default values of some configuration parameters that are present in PHPStan itself. These parameters are documented on phpstan.org.

About

Extra strict and opinionated rules for PHPStan

Topics

Resources

License

Security policy

Stars

Watchers

Forks

Packages

No packages published

Contributors 31