Doc #64058 [Csd]: Warn about register_globals

From: Date: Thu, 24 Jan 2013 19:20:18 +0000
Subject: Doc #64058 [Csd]: Warn about register_globals
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-9470@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64058&edit=1 ID: 64058 User updated by: ph57 at brisk dot org dot uk Reported by: ph57 at brisk dot org dot uk Summary: Warn about register_globals Status: Closed Type: Documentation Problem Package: Documentation problem Operating System: n/r PHP Version: 5.3.21 Assigned To: krakjoe Block user comment: N Private report: N New Comment: Actually it doesn't mention the linkage between $_SESSION keys and global variables anywhere in the SESSION documentation (although I think I did find a posting by someone somewhere in there that obliquely alerted me to the issue, but I don't think one should have to read all the postings which are often long or old). Yesterday I hadn't even heard of register_globals (why read about deprecated features?). Now I know what it is, having spent the whole of yesterday afternoon investigating why my session vars were changing under my feet. I wouldn't have made this mistake if there had been a mention of this issue in the SESSION documentation. Previous Comments: ------------------------------------------------------------------------ [2013-01-24 16:47:14] philip@php.net I thought we already mentioned this, or do somewhere else. Does someone else remember? There are plenty of PHP 5.3 (and below) users out there. We document PHP 5.1 and above. ------------------------------------------------------------------------ [2013-01-24 13:45:17] ph57 at brisk dot org dot uk It is a pity that, even when serious deficiencies are drawn to your attention, you arrogantly refuse to correct them. The fact that register_globals is a deprecated feature is not relevant. The fact is there is absolutely no mention of register_globals, or its appalling side-effects, in the SESSION documentation. So it is possible for someone, like myself, to read the whole of the SESSION documentation, and use it, whilst remaining completely ignorant of this underlying disaster. I simply askled you to warn people. You refuse. That is a very bad decision. I won't bother to try to help you improve in future. Goodbye. ------------------------------------------------------------------------ [2013-01-24 12:35:49] krakjoe@php.net http://php.net/manual/en/ini.core.php#ini.register-globals register_globals is a deprecated feature in the version of PHP you are reported to be using. It is removed in the final release after it. Therefore there is no need to include any more information than is included in the manual page I have linked to. ------------------------------------------------------------------------ [2013-01-23 20:14:27] ph57 at brisk dot org dot uk Description: ------------ --- From manual page: http://uk1.php.net/manual/en/session.examples.basic.php --- Please can we have a very prominent WARNING, in the introduction to session, along the lines of:- WARNING: if register_globals is set ON, then any key you use in $_SESSION will be a reference to a global variable of the same name. This will cause your session vasriables to change unexpectedly if you accidentally use a key that happens to match the name of an existing global variable. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=64058&edit=1

« previous php.doc.bugs (#9470) next »