Re: [VOTE] Same Site Cookie RFC

From: Date: Sat, 21 Jul 2018 23:21:43 +0000
Subject: Re: [VOTE] Same Site Cookie RFC
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-102945@lists.php.net to get a copy of this message
On Sat, Jul 21, 2018 at 11:26 PM Andrey Andreev <narf@devilix.net> wrote: > Yes. > > All other "options" are actual *cookie attribute* names, as defined by > the various IETF RFCs, while "lifetime" is just a convenient name used > by PHP. It doesn't correspond to a particular attribute, but instead > the values for the Expires and Max-Age attributes are derived from it. > I believe during discussion I insisted that the parameter be called > "attributes", for this very reason. > Hi, While I do understand your reasoning, I find it extremely unfriendly to the user of the function to ask for one parameter separate from all the others for that reason alone. Also, keep in mind that all this function does is set the session.cookie_* ini entries. So all parameters are treated equally. > On another note, I also wanted that pretty much any key/value pair to > be accepted instead of raising an error, for forward compatibility. > I really believe that the user spotting errors like `['expries' => time() + 3600]` faster is more valuable than FC. Regards, Pedro

« previous php.internals (#102945) next »