Re: [VOTE] RFC: Introduce session_start() options - read_only, unsafe_lock, lazy_write and lazy_destroy
| From: | Yasuo Ohgaki | Date: | Thu, 06 Mar 2014 20:34:32 +0000 |
| Subject: | Re: [VOTE] RFC: Introduce session_start() options - read_only, unsafe_lock, lazy_write and lazy_destroy | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72983@lists.php.net to get a copy of this message | ||
Hi Peter,
On Mon, Mar 3, 2014 at 7:56 PM, Peter Cowburn <petercowburn@gmail.com>wrote:
> Is this vote still in-progress? The RFC page says yes, but the closing
> date has long-since passed.
Thank you for reminding.
Proposal 1 is passed 9 vs 1.
Proposal 2 and 3 is declined 1 vs 7 and 1 vs 6.
Lazy deletion is design bug fix. This issue cannot be solved without
delayed deletion due to technical reason of current web technology. This
also involves session security. Current implementation allows attackers to
exploit stolen session as long as they want also.
I'll come back on this issue later.
Thank you for voting all!
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net