Re: [Pre-RFC] Pure-code source files via .phpc extension

From: Date: Thu, 28 May 2026 09:10:22 +0000
Subject: Re: [Pre-RFC] Pure-code source files via .phpc extension
References: 1 2 3 4 5 6 7 8 9  Groups: php.internals 
Request: Send a blank email to internals+get-131034@lists.php.net to get a copy of this message
I see a security concern in introducing a new file extension. It's common to configure a web server to pass locations that end with .php to a PHP interpreter. Nginx example: ``` location ~ \.php$ { include snippets/fastcgi-php.conf; fastcgi_pass unix:/run/php/php8.2-fpm.sock; } ``` Apache2 example: ``` <FilesMatch \.php$> SetHandler application/x-httpd-php </FilesMatch> ``` With a new file extension, users would be forced to change their configs, or a direct request to .phpX file would expose its source code. This will come as a surprise to users who don't know about the pure syntax yet include libraries that use it.

« previous php.internals (#131034) next »