Re: [RFC][Discussion] Add #[NoSerialize] attribute for excluding properties or classes from serialization
| From: | Tim Düsterhus | Date: | Fri, 07 Nov 2025 10:57:22 +0000 |
| Subject: | Re: [RFC][Discussion] Add #[NoSerialize] attribute for excluding properties or classes from serialization | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-129130@lists.php.net to get a copy of this message | ||
Hi
Am 2025-11-07 01:13, schrieb Dmytro Kulyk:
I’ve updated the RFC to include the new class-level behavior — applying #[NoSerialize] to a class now forbids its serialization by throwing, using the same internal mechanism as built-in non-serializable classes (e.g., CurlHandle, Random\Engine\Secure). This update aligns the proposal with existing engine semantics and unifies both property-level skipping and class-level prohibition under a single attribute. The inheritance model has also been clarified: class-level #[NoSerialize] is inherited (“sticky”) and cannot be overridden in subclasses. Updated RFC: https://wiki.php.net/rfc/no_serialize_attributeThank you. The updated RFC is looking good to me. I also appreciate that you kept a changelog within the RFC. One thing you could mention and that should be done as part of the RFC is migrating all existing classes with
@not-serializable to make use of the attribute instead. That's also what has been done when the #[\Deprecated] attribute was introduced. Other than that, I don't have any further comments.
Best regards
Tim Düsterhus