Re: [Pre-RFC] Pure-code source files via .phpc extension
| From: | go dot al dot ni at gmail dot com | Date: | Thu, 28 May 2026 09:10:22 +0000 |
| Subject: | Re: [Pre-RFC] Pure-code source files via .phpc extension | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-131034@lists.php.net to get a copy of this message | ||
I see a security concern in introducing a new file extension.
It's common to configure a web server to pass locations that end with .php
to a PHP interpreter.
Nginx example:
```
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/run/php/php8.2-fpm.sock;
}
```
Apache2 example:
```
<FilesMatch \.php$>
SetHandler application/x-httpd-php
</FilesMatch>
```
With a new file extension, users would be forced to change their configs,
or a direct request to .phpX file would expose its source code.
This will come as a surprise to users who don't know about the pure syntax
yet include libraries that use it.