[php-src] Issue #12080: Add expose_php option with reduced precision
| From: | Krinkle | Date: | Wed, 30 Aug 2023 01:45:59 +0000 |
| Subject: | [php-src] Issue #12080: Add expose_php option with reduced precision | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-245288@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/12080
Author: Krinkle
### Description
As @krakjoe [pointed out](https://github.com/php/php-src/pull/3335#issuecomment-836582485) at https://github.com/php/php-src/pull/3335, the
popular default configurations are decided by package managers and hosting providers, and the
default already has expose_php enabled.
But, we also know that those same package managers and hosting providers feel their only option is
to turn this off as a sort of security through obscurity. This in turn can deminish global
statistics (e.g. [W3 Techs](https://w3techs.com/technologies/details/pl-php)).
Perhaps we could offer a middleground that would appeal to some of the package managers (e.g.
Debian, Fedora), and major hosting providers to no longer turn it off completely. For example:
```
X-Powered-By: PHP/8.2.9
```
… could be reduced to:
```
X-Powered-By: PHP
```
One could instead consider preserving major or major+minor version. But, I think an option that
controls simply whether the version is obscured is more likely to receive broad adoption, and keeps
the API simpler to maintain and to consume (also crawlers interpreting and aggregating this
information).