Skip to content

UnSafeIsSetOverArray ​

warning on by default quick-fix

Group: Control flow · PhpStorm name: UnSafeIsSetOverArrayInspection

isset() mixes two questions: "does the key/variable exist" and "is it not null". This rule points out single-argument isset() calls where a more explicit construct says what is meant: a plain !== null comparison for variables and declared properties, array_key_exists() for array keys, and flags concatenated index expressions that should be computed beforehand.

Example ​

Options: all three true, regular comparison style.

php
<?php
$grid = [];
if (isset($grid['r' . $row])) {
    $both = isset($grid['a'], $grid['b']);
    $cell = isset($grid['k']) ? $grid['k'] : NULL;
    $cell = !isset($grid['k']) ? null : $grid['k'];
    print isset($grid[$col]);
    $seen = !isset($grid['r' . $row]);
}
$top = isset($grid);

class Ledger {
    public $total;
    public function check(\ArrayAccess $bag, $field) {
        $tmp = new stdClass();
        $u = isset($bag['x']);
        $v = isset($tmp->anything);
        $w = isset($this->$field);
        $p = isset($this->total);
        $q = !isset($tmp);
        try {
            return 1;
        } finally {
            $r = isset($tmp);
        }
    }
}
php
<?php
$grid = [];
if (isset($grid['r' . $row])) {
    $both = isset($grid['a'], $grid['b']);
    $cell = isset($grid['k']) ? $grid['k'] : NULL;
    $cell = !isset($grid['k']) ? null : $grid['k'];
    print isset($grid[$col]);
    $seen = !isset($grid['r' . $row]);
}
$top = isset($grid);

class Ledger {
    public $total;
    public function check(\ArrayAccess $bag, $field) {
        $tmp = new stdClass();
        $u = isset($bag['x']);
        $v = isset($tmp->anything);
        $w = isset($this->$field);
        $p = $this->total !== null;
        $q = $tmp === null;
        try {
            return 1;
        } finally {
            $r = isset($tmp);
        }
    }
}

Reported:

  • line 3: Compute the concatenated key in a variable before using it.
  • line 7: Use array_key_exists() to check for the key itself.
  • line 8: Use array_key_exists() to check for the key itself.
  • line 19: Compare with null instead: '$this->total !== null'.
  • line 20: Compare with null instead: '$tmp === null'.

Options ​

OptionTypeDefaultEffect
SUGGEST_TO_USE_ARRAY_KEY_EXISTSboolfalseEnables D10.
SUGGEST_TO_USE_NULL_COMPARISONboolfalseEnables D8 and its fix.
REPORT_CONCATENATION_IN_INDEXESbooltrueEnables D9. When off, such accesses go straight to D10.

All upstream fixtures run with all three options on and regular comparison style.

Configure ​

In custos.json:

json
{
  "rules": {
    "UnSafeIsSetOverArray": {
      "enabled": false,
      "options": {
        "SUGGEST_TO_USE_ARRAY_KEY_EXISTS": false,
        "SUGGEST_TO_USE_NULL_COMPARISON": false,
        "REPORT_CONCATENATION_IN_INDEXES": true
      }
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore UnSafeIsSetOverArray

/**
 * @noinspection UnSafeIsSetOverArrayInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.