I mean, what could possibly go wrong with untestable code and unfiltered input...?
I mean, what could possibly go wrong with untestable code and unfiltered input...?
The code is actually pretty tight and is optimized for empowering a developer rather than inflating the bumpers of your bowling lane.
Unfiltered input? You realise that this is a router, right? The only 'input' is the URL path.
I really wish you could be more specific about these 'worst practices' that make this 91-line library an 'unmaintainable mess and security hole'.
And how is this untestable, exactly? It's really easy to fake http requests in php-cli from a unit test, for instance. And is there any other way you'd want to test a router than by faking php requests? I somewhat wonder whether the fact that this happens to be PHP biased your judgment.
It's a clean separation of concerns - the router is the only thing that knows about the URL implementation. The rest of the code relies on the router to do that. That's a good practice to me.
What would you would consider "best practice" in place of a router?