Req #39635 [Opn->Sus]: Better control for serialization (keyword for permit property serialization)

From: Date: Thu, 13 Feb 2020 17:28:51 +0000
Subject: Req #39635 [Opn->Sus]: Better control for serialization (keyword for permit property serialization)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225567@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=39635&edit=1 ID: 39635 Updated by: cmb@php.net Reported by: t dot prochazka at centrum dot cz Summary: Better control for serialization (keyword for permit property serialization) -Status: Open +Status: Suspended Type: Feature/Change Request Package: *General Issues Operating System: * PHP Version: * Block user comment: N Private report: N New Comment: > PHP has no advanced support for serialization. PHP has already different ways to customize serialization, namely __sleep()[1] and Serializable[2], the latter being superseeded by __serialize()[3] as of PHP 7.4.0. Adding support for the transient keyword (or similar) *might* make sense, but that should be discussed on the internals mailing list[4]. Feel free to start that discussion; for the time being, I'm suspending this ticket. [1] <https://www.php.net/manual/en/language.oop5.magic.php#object.sleep> [2] <https://www.php.net/manual/en/class.serializable.php> [3] <https://www.php.net/manual/en/migration74.new-features.php#migration74.new-features.standard.magic-serialize> [4] <https://www.php.net/mailing-lists.php#internals> Previous Comments: ------------------------------------------------------------------------ [2015-06-23 21:06:40] chealer at gmail dot com I think we should rather ease serialization customization. If we could simply adjust the object before serialization, use the default serialization, then adjust tje object after a default unserialization, we could solve this case by simply unsetting problematic properties before serialization. ------------------------------------------------------------------------ [2009-11-09 16:23:56] scottmac@php.net Patch already exists, just need to discuss when is the correct time to add it. http://whisky.macvicar.net/patches/php-transient.diff.txt ------------------------------------------------------------------------ [2009-11-09 15:53:54] tjerkw at gmail dot com Using a transient keyword is better because if we have the following case: class A { $a; $b; } class B extends A { $c function __sleep() { return array("c"); } } now if you serialize b you will not serialize the $a and $b members from class A. So the sleep functions actually changes the encapsulated behaviour of A. Or we should call the superclass A::__sleep() method and join that with the new arrow. However this is much cleaner code. And wether a member is transient or not should be declered nearby the member to keep else other developers may not now wether the member will be serialized or not. ------------------------------------------------------------------------ [2007-01-25 15:54:50] spam at thishell dot com While it is possible to exclude members from serialization using __sleep(), it has downsides: - Using get_object_vars($this) to return the members is extremely slow - Manually maintaining an array with the members is error prone and can be quite some work A transient keyword to exclude members from serialization would make it easier ... ------------------------------------------------------------------------ [2006-11-26 11:40:40] t dot prochazka at centrum dot cz Description: ------------ PHP has no advanced support for serialization. I think, that is problem, that PHP serialize all properties. What about add single keyword (as transient) for property which can't be serializable? Example: class Foo { public $a; public transient $b; } Description of Java transient keyword: http://java.sun.com/docs/books/jls/second_edition/html/classes.doc.html#78119 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=39635&edit=1

« previous php.bugs (#225567) next »