Re: PHP Weekly Summary (Issue 2)
| From: | Sterling Hughes | Date: | Sun, 10 Sep 2000 18:08:57 +0000 |
| Subject: | Re: PHP Weekly Summary (Issue 2) | ||
| References: | 1 | Groups: | php.dev php.general |
| Request: | Send a blank email to php-dev+get-32828@lists.php.net to get a copy of this message | ||
> BUG: SRADV00001, PHP file upload security vulnerability
> -------------------------------------------------------
> ** <snip> **
>
> <editorial mode="soap-box">
> Jon is not a stupid guy. Throughout the 3 or so days when every message
> submitted to the list was basically part of the thread that he started, he
> had some very valid points. In most areas, his theory was sound. The main
> problem was implementation. The way he went about speaking to members of
> the list was very, very blunt - and not within the "expected" norms of net
> etiquette. Whether he was right or wrong in doing so is not the issue,
> but *is* what led to the upset of those involved. A personal observation -
> if you (the reader) are posting to the developers list with a problem,
> try to phrase it in such a way that puts across your point without dumping
> on the hard work of those (mostly *unpaid* volunteers) who work on
> PHP. Doing so will get your problem solved quickly and without fuss.
> </editorial>
>
Let me just clarify this a little bit, most of the members of the list were
curteous and all of the members of the PHP Group and the core dev's were
responsive and polite, listening to his points, despite his excessive rudeness
(I shudder to think what would've happened if a he posted that type of message
to perl5-porters:=). The beginning of the thread can be found at
http://marc.theaimsgroup.com/?l=php-dev&m=96815056226694&w=2
> Much work has been done in the last week to make changes to the
> documentation to reflect the possible security hazards discussed above,
> and to modifying the default behavior of PHP itself. There is also talk
> of a code audit, and the possible formation of a team dedicated to doing
> it on a permanent basis. Anyone out there interested should post to the
> list.
>
>
> NEW: Apache ICU i16n
> --------------------
> Carl W. Brown has been hard at work for multiple charset conversion and
> support for PHP3&4 using Apache ICU.
>
>
> REQ: PHP extension documentation
> --------------------------------
> The number of requests for documentation on how to write a PHP extension
> is rising. Anyone who can help in this area, please do.
>
> for the time being, the README.SELF-CONTAINED-EXTENSIONS, README.EXT_SKEL,
> apidoc.txt and apidoc-zend.txt files from the PHP source distribution are
> a good starting point.
>
> I understand that "Web Application Development With PHP" (ISBN:0735709971)
> has a section about this topic also. (see
> http://www.phpwizard.net/book/
> for more information. note: i am not affiliated with the authors of this
> book in any way, nor have i read it.).
>
>
Web Application Development with PHP (which IMHO is a great book) contains the
"official" Zend API documentation. This should be freely avaialable sometime
soon I believe, I saw a Zend commit message with the contents of the
documentation, however, I haven't seen it on the web site.
<shameless-self-promo>
Also I'll be writing an article for the January issue of Webtechniques ("Open
Source: State of the Union") covering "Extending PHP4." I believe this will
also be made available online. For anyone going to Apachecon you can check out
my talk on Extending PHP4. And finally "The PHP Developer's Cookbook" written
by myself with Andrei Zmievski coming out this November (to a book store near
you:-) has a chapter devoted to the Zend API.
</shameless-self-promo>
> REQ: function aliases
> ---------------------
> a request was made again to be able to create a new name or redefine the
> functionality of an existing function. according to previous feedback from
> the core developers, it is unlikely this feature will find its way
> into PHP. (if it does, it will be very limited for security reasons).
>
>
> NEW: XSLT extension
> -------------------
> Sterling Hughes and Derick Rethans continue to make headway on their
> (highly anticipated) sablotron-based XSLT extension. There were a few
> rumblings about the possibility of a xalan-based extension, but seeings as
> the xalan-c++ library is still alpha, i doubt it'll be finished before
> Sterling and Derick's.
>
The Sablotron XSL extension is, for the most part, ready for primetime, I'll be
commiting a slightly modified version which takes out some unneccessary error
checking and adds some additional error information sometime tuesday. But the
API is pretty solid.
>
> FIX: include[_once],require[_once] inconsistent
> -----------------------------------------------
> John from Webmeta spotted a small glitch in the functionality of
> require_once that has now been fixed in CVS.
>
>
> --
>
> About 1100 messages made their way onto the php-dev list this
> week, with a large amount of them being bug reports being worked
> on. A hearty "good job!" to the PHP QA team who continue to
> methodically burn through the large amount of bugs that are filed.
>
> Some good news for "the summary". I've had three separate offers for
> hosting, the final details of which I am hoping to get wrapped up in the
> next week or so. Thanks also to everyone who contacted me with feedback
> for Issue 1. I am really enjoying doing these, and all responses so far
> have been quite encouraging.
>
I'm really enjoying reading these. :)
-Sterling