Bug #15969 Updated: Observation on deprecation of register_globals
| From: | sterling@php.net | Date: | Tue, 02 Jul 2002 21:11:21 +0000 |
| Subject: | Bug #15969 Updated: Observation on deprecation of register_globals | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-12870@lists.php.net to get a copy of this message | ||
ID: 15969
Updated by: sterling@php.net
Reported By: colins@infofind.com
-Status: Feedback
+Status: Bogus
Bug Type: PHP options/info functions
Operating System: Linux
PHP Version: 4.1.2
New Comment:
Btw, profound observations of the meaning of depreciated are best left
to private mail.
Previous Comments:
------------------------------------------------------------------------
[2002-06-01 19:27:12] philip@php.net
I'm going to assume that register_globals will forever be an available
PHP directive (I hope so). Especially after seeing the impact changing
the default to off has made. Is there an official word on this?
Btw, I like the latin definition too :)
------------------------------------------------------------------------
[2002-03-10 13:02:26] colins@infofind.com
Philip,
Thanks for the PHP definition of "deprecated". The American Heritage
Dictionary defines it as "To expressly disapprove of; protest or plead
against - from the latin deprecari - to ward off by prayer". (I like
the latin definition <grin>.)
I think the usage in software circles is generally taken to mean "this
is going away sometime in the future".
In any definition, I reinterate my original statement that I lobby for
it never going away, just defaulting to NO with the option to set to
YES in the INI (effectively as the php.ini-recommended has it now.)
Colin
------------------------------------------------------------------------
[2002-03-09 14:51:27] philip@php.net
In PHP, deprecated means "Maybe one day it won't work but not sure
if/when that'll be exactly, here's why you shouldn't use this..." I
assume register_globals will work for awhile, and nobody knows when (or
if) it won't (yet).
So the question is "When will register_globals not work?" A good
question indeed. Not a documentation problem as nobody has the answer,
yet.
------------------------------------------------------------------------
[2002-03-09 14:09:21] philip@php.net
See also: import_request_variables() and extract() for ways to deal
with this issue.
------------------------------------------------------------------------
[2002-03-09 13:22:58] colins@infofind.com
I think maybe one of us is missing the point (and it's probably me!).
php.ini-recommended says:
"Note that register_globals is going to be depracated (sic)(i.e.,
turned off by default) in the next version of PHP, because it often
leads to security bugs."
I take this to mean that register_globals will off permanently and
cannot be turned back on, even in the INI.
But if it means that it will default to OFF but can still be turned ON
in the INI, then I have no complaint. This would protect the novice
but allow those who understand the implications to turn it on.
Although the latter doesn't sound to be any more than how the
distribution INIs are written.
My issue is not the wisdom of having it ON or OFF, just the wisdom of
taking away the option of choosing from the PHP system administrator.
Avaliability of functions like that suggested by sniper are fine, but
would still take a huge effort to change all the code and the potential
is high for breaking any part of it by missing one place to add the
function.
You comments and thoughts are appreciated.
Colin
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/15969
--
Edit this bug report at http://bugs.php.net/?id=15969&edit=1