Bug #61233 [Com]: xsl.security_prefs is not documented
| From: | os3476 at ithink dot ch | Date: | Fri, 19 Oct 2012 07:13:05 +0000 |
| Subject: | Bug #61233 [Com]: xsl.security_prefs is not documented | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-8977@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=61233&edit=1
ID: 61233
Comment by: os3476 at ithink dot ch
Reported by: sixd@php.net
Summary: xsl.security_prefs is not documented
Status: Assigned
Type: Bug
Package: Documentation problem
Operating System: All
PHP Version: 5.4.0
Assigned To: chregu
Block user comment: N
Private report: N
New Comment:
What about this?
@@ -42,2 +42,2 @@
- When you introduce a new configuration option, set its in-code default value
(when no value is given in any ini file) to the desired default value;
+ When you introduce a new configuration option whose desired default value
breaks existing code, set its in-code default value (when no value is given in
any ini file) to having no effect at all compared to the previous version, and
add it with the desired default value to the php.ini.dist (or whatever you call
it) file, so that people who upgrade see the new option and can anticipate the
problems;
+
@@ -44,2 +44,2 @@
- When someone submits a patch that looks urgent because of security issues,
accept it as quickly as possible.
+ When someone submits a patch, no matter how urgent it may seem to apply it,
check if the corresponding documentation was written before accepting it; /* I
take it you donât release code unless it includes the corresponding unit tests.
Documentation is the same. */
+
@@ -46,0 +46,2 @@
+ To that effect, make sure everyone who submits a patch know how they can be
anonymously constructive about documentation as well;
+
@@ -46,2 +48,2 @@
- Provide online documentation for the latest version of PHP;
+ Provide a documentation archive, so that people can consult documentation that
matches the PHP version they use and not just the latest that they likely canât
use because of their hosting provider, LTS Linux distribution, company policy or
whatever reason;
+
There. Thatâs a constructive patch to your methodology that Iâm submitting. Let
me know when it makes it to the master branch.
Previous Comments:
------------------------------------------------------------------------
[2012-10-15 07:11:34] sixd@php.net
@os3476 if the code/package author is unable to make a change for whatever
reason, feel free to be constructive and help the PHP community by submiting a
doc edit at https://edit.php.net/ Anonymous users can submit
patches.
------------------------------------------------------------------------
[2012-10-15 06:57:16] os3476 at ithink dot ch
Documented in the PHP documentation. You know, the web site where you go when
something does not workâ¦
------------------------------------------------------------------------
[2012-10-12 02:13:11] sixd@php.net
From NEWS:
- XSL:
. Added xsl.security_prefs ini option to define forbidden operations within
XSLT stylesheets, default is not to enable write operations. This option
won't be in 5.4, since there's a new method. Fixes Bug #54446. (Chregu,
Nicolas Gregoire)
------------------------------------------------------------------------
[2012-10-11 10:23:05] os3476 at ithink dot ch
Is this for real? An new option has a default value that cripples XSLTProcessor
WITH ITS DEFAULT VALUE and itâs UNDOCUMENTED?
------------------------------------------------------------------------
[2012-03-02 01:21:53] sixd@php.net
Description:
------------
xsl.security_prefs is in PHP 5.3 php.ini-* but does not appear in the
documentation.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=61233&edit=1