Edit report at https://bugs.php.net/bug.php?id=77378&edit=1
ID: 77378
User updated by: olafvdspek at gmail dot com
Reported by: olafvdspek at gmail dot com
Summary: Default to short_open_tags = false
Status: Open
Type: Feature/Change Request
Package: *General Issues
PHP Version: 7.3.0
Block user comment: N
Private report: N
New Comment:
Does --disable-short-tags 'only' change the default or does it disable short tags
unconditionally, even if short_open_tags = true in the .ini?
Previous Comments:
------------------------------------------------------------------------
[2019-01-02 09:16:38] nikic@php.net
The summarize the current situation, because it's rather odd:
* In both php.ini-production and php.ini-development short_open_tag is off.
* The default value (without ini) is short_open_tag=on *unless* --disable-short-tags has been
specified during ./configure. On Windows there doesn't seem to be an equivalent for
--disable-short-tags, so on Windows the default is always on.
I agree that the current situation is quite odd. It would probably make sense to make
short_open_tag=off the default and convert --disable-short-tags into --enable-short-tags for people
who would like to influence the default.
------------------------------------------------------------------------
[2018-12-31 10:31:13] olafvdspek at gmail dot com
In a world where the effective value is set in php.ini rather then the php binary for a majority of
users.
If you're really afraid of changing the default there's a third option: remove the default
and require the value to be explicitly set.
------------------------------------------------------------------------
[2018-12-31 04:53:04] spam2 at rhsoft dot net
in which world is when "you change the default" the same as "That's already the
case with the php.ini change"?
------------------------------------------------------------------------
[2018-12-31 02:13:35] olafvdspek at gmail dot com
> there are two things:http://php.net/manual/en/ini.core.php#ini.short-open-tag
doesn't mention any of this.
> when you change that default on any existing environment you probably leak code and credentials
> without taking notice
That's already the case with the php.ini change.
------------------------------------------------------------------------
[2018-12-30 19:00:57] spam2 at rhsoft dot net
there are two things:
* it's recommended for years to tun it off
* turning it off has security risks
when you change that default on any existing environment you probably leak code and credentials
without taking notice
if you care your "php.ini" would have it disabled for years and if you don#t care changing
the default only introduces problems with no gain
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77378
--
Edit this bug report at https://bugs.php.net/bug.php?id=77378&edit=1