Req #77378 [Opn]: Default to short_open_tags = false
| From: | olafvdspek at gmail dot com | Date: | Mon, 31 Dec 2018 02:13:35 +0000 |
| Subject: | Req #77378 [Opn]: Default to short_open_tags = false | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218694@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77378&edit=1
ID: 77378
User updated by: olafvdspek at gmail dot com
Reported by: olafvdspek at gmail dot com
Summary: Default to short_open_tags = false
Status: Open
Type: Feature/Change Request
Package: *General Issues
PHP Version: 7.3.0
Block user comment: N
Private report: N
New Comment:
> there are two things:
http://php.net/manual/en/ini.core.php#ini.short-open-tag
doesn't mention any of this.
> when you change that default on any existing environment you probably leak code and credentials
> without taking notice
That's already the case with the php.ini change.
Previous Comments:
------------------------------------------------------------------------
[2018-12-30 19:00:57] spam2 at rhsoft dot net
there are two things:
* it's recommended for years to tun it off
* turning it off has security risks
when you change that default on any existing environment you probably leak code and credentials
without taking notice
if you care your "php.ini" would have it disabled for years and if you don#t care changing
the default only introduces problems with no gain
------------------------------------------------------------------------
[2018-12-30 18:55:39] olafvdspek at gmail dot com
Description:
------------
AFAIK the recommendation has been false for quite some time but the default (and docs) don't
reflect this. Could this inconsistency be rectified?
http://php.net/manual/en/ini.core.php#ini.short-open-tag
https://github.com/oerdnj/deb.sury.org/issues/1043
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77378&edit=1