Re: RFC: Implementing a core anti-XSS escaping class
| From: | Pádraic Brady | Date: | Fri, 21 Sep 2012 09:46:53 +0000 |
| Subject: | Re: RFC: Implementing a core anti-XSS escaping class | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-63211@lists.php.net to get a copy of this message | ||
Hi Pierre,
I also noticed your tweet ;).
> Given the current discussions about the APIs (see my other reply too)
> and its usage, and that this proposal is non invasive/self contained
> in an extension, I would strongly suggest to already go with it in
> PECL, do releases (stay alpha until you have a very good feeling about
> the API stability), etc. It will also greatly help to get more
> feedback.
>
> Then it could be proposed again for being bundled at some point,
> before we go features freeze for 5.5.
I believe this is the path we'll be taking after some IRC discussions.
Though, I do think that taking the RFC route on this one was the only
realistic option for a PHP programmer with a minimal C skillset. It
ensured that the proposal gained exposure, lots of feedback and an
opportunity to pick up a real C programmer who could take it further.
In any case, hopefully I'll be back with real hardcore C code for PHP
5.5. In the meantime, if anyone has any lingering concerns or
questions about the RFC, let me know!
Paddy
--
Pádraic Brady
http://blog.astrumfutura.com
http://www.survivethedeepend.com
Zend Framework Community Review Team