Re: Re: PHP 8 is_file/is_dir input handling
| From: | privat) | Date: | Tue, 01 Dec 2020 20:13:27 +0000 |
| Subject: | Re: Re: PHP 8 is_file/is_dir input handling | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-112359@lists.php.net to get a copy of this message | ||
Am 01.12.20 um 21:09 schrieb Stanislav Malyshev:
my server would trigger a mail every 15 minutes wioth all warnings and notices to enforce fixing the issuewe are running error_reporting E_ALL for 17 years now and don't distinct between notice / warning / error, it has to be fixed - periodSurely you do. Your code continues to run after warning/notice but stops after the error. It's impossible to ignore that. Unless you have an error handler that does exit() after a notice (which I have hard time believing, honestly, but who knows), there is a very major distinction.
It's not about what "has to be fixed" - it's not about the contents of your bug tracking database - it's about the code that run one way and suddenly now runs (or, rather, fails) in a fundamentally different way it should fail and it should have done that for 20 years because it points out missing input validation which is a much bigger probkem than a random exception seems to bebut yeah, you are the guy closing security bugs all the time with no understanding what "fail eraly and fail safe" means in the context of security