Req #77378 [Opn]: Default to short_open_tags = false

From: Date: Wed, 02 Jan 2019 09:27:51 +0000
Subject: Req #77378 [Opn]: Default to short_open_tags = false
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218731@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77378&edit=1 ID: 77378 Updated by: nikic@php.net Reported by: olafvdspek at gmail dot com Summary: Default to short_open_tags = false Status: Open Type: Feature/Change Request Package: *General Issues PHP Version: 7.3.0 Block user comment: N Private report: N New Comment: @olafvdspek It only changes the default. The ini setting still wins in the end. I've sent a mail to internals regarding this issue: https://marc.info/?l=php-internals&m=154642087106001 Previous Comments: ------------------------------------------------------------------------ [2019-01-02 09:22:02] olafvdspek at gmail dot com Does --disable-short-tags 'only' change the default or does it disable short tags unconditionally, even if short_open_tags = true in the .ini? ------------------------------------------------------------------------ [2019-01-02 09:16:38] nikic@php.net The summarize the current situation, because it's rather odd: * In both php.ini-production and php.ini-development short_open_tag is off. * The default value (without ini) is short_open_tag=on *unless* --disable-short-tags has been specified during ./configure. On Windows there doesn't seem to be an equivalent for --disable-short-tags, so on Windows the default is always on. I agree that the current situation is quite odd. It would probably make sense to make short_open_tag=off the default and convert --disable-short-tags into --enable-short-tags for people who would like to influence the default. ------------------------------------------------------------------------ [2018-12-31 10:31:13] olafvdspek at gmail dot com In a world where the effective value is set in php.ini rather then the php binary for a majority of users. If you're really afraid of changing the default there's a third option: remove the default and require the value to be explicitly set. ------------------------------------------------------------------------ [2018-12-31 04:53:04] spam2 at rhsoft dot net in which world is when "you change the default" the same as "That's already the case with the php.ini change"? ------------------------------------------------------------------------ [2018-12-31 02:13:35] olafvdspek at gmail dot com > there are two things: http://php.net/manual/en/ini.core.php#ini.short-open-tag doesn't mention any of this. > when you change that default on any existing environment you probably leak code and credentials > without taking notice That's already the case with the php.ini change. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77378 -- Edit this bug report at https://bugs.php.net/bug.php?id=77378&edit=1

« previous php.bugs (#218731) next »