#37532 [NEW]: Allow override of Exception::getTrace()

From: Date: Fri, 19 May 2006 22:59:43 +0000
Subject: #37532 [NEW]: Allow override of Exception::getTrace()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-97394@lists.php.net to get a copy of this message
From: spam01 at pornel dot net Operating system: * PHP version: 5.1.4 PHP Bug Type: Feature/Change Request Bug description: Allow override of Exception::getTrace() Description: ------------ Exception::getTrace() is final. Because of that it's not possible to override it in order to hide backtrace when it contains sensitive data. I'm developing library and I'd like to throw exceptions from sensitive context without messing default handlers. I realize that client's code is supposed to catch exceptions or disable reporting, but I can't believe that everyone will RTFM and comply. This issue also affects PDO. It would be nice if it could hide passwords instead of just having this risk documented. Reproduce code: --------------- class StealthFoolproofException extends Exception { function getTrace() {return NULL;} } function test($secretpassword) { throw new StealthFoolproofException(); } test('don\'t reveal that'); Expected result: ---------------- PHP Error: Fatal error: Uncaught exception StealthFoolproofException ... Stack trace: none. Actual result: -------------- Cannot override final method Exception::getTrace(). If not overriden, reveals arguments. -- Edit bug report at http://bugs.php.net/?id=37532&edit=1 -- Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=37532&r=trysnapshot44 Try a CVS snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=37532&r=trysnapshot52 Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=37532&r=trysnapshot60 Fixed in CVS: http://bugs.php.net/fix.php?id=37532&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=37532&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=37532&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=37532&r=needscript Try newer version: http://bugs.php.net/fix.php?id=37532&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=37532&r=support Expected behavior: http://bugs.php.net/fix.php?id=37532&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=37532&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=37532&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=37532&r=globals PHP 3 support discontinued: http://bugs.php.net/fix.php?id=37532&r=php3 Daylight Savings: http://bugs.php.net/fix.php?id=37532&r=dst IIS Stability: http://bugs.php.net/fix.php?id=37532&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=37532&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=37532&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=37532&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=37532&r=mysqlcfg

« previous php.bugs (#97394) next »