Re: [RFC] [VOTE] Deprecate PHP's short open tags
| From: | Benjamin Eberlei | Date: | Thu, 25 Apr 2019 10:03:47 +0000 |
| Subject: | Re: [RFC] [VOTE] Deprecate PHP's short open tags | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-105443@lists.php.net to get a copy of this message | ||
On Wed, Apr 24, 2019 at 1:29 PM G. P. B. <george.banyard@gmail.com> wrote:
> Hello Internal,
>
> The two weeks of voting have now ended.
> The results are 38 for and 18 against (total 56) for the primary vote to
> deprecate PHP's short open tag in PHP 7.4.
> This passes in favor with 68%.
>
> The results are 42 for and 15 against (total 57) for the secondary vote to
> remove PHP's short open tag in PHP 8.
> This passes in favor with 74%.
>
> Thanks for everyone who voted on this issue.
>
> Best regards
>
> George P. Banyard
>
The RFC doesn't mention to much details on the exact implementation of this
removal, but to avoid the potential security nightmare of <? code to
suddenly be printed to screens when people upgrade to 8.0 I would suggest
(props to Bob who mentioned this idea) that we at least keep the INI option
indefinitely and when set to On always cause a fatal error in RINIT with an
error message that mentions the security implications of disabling it and
potentially linking to a PHP documentation page that offers solutions on
how to migrate. This page could also be linked in the deprecation error
message in 7.4
>
> >
>