Re: [VOTE] RFC: Introduce session_start() options - read_only, unsafe_lock, lazy_write and lazy_destroy

From: Date: Thu, 06 Mar 2014 20:34:32 +0000
Subject: Re: [VOTE] RFC: Introduce session_start() options - read_only, unsafe_lock, lazy_write and lazy_destroy
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-72983@lists.php.net to get a copy of this message
Hi Peter, On Mon, Mar 3, 2014 at 7:56 PM, Peter Cowburn <petercowburn@gmail.com>wrote: > Is this vote still in-progress? The RFC page says yes, but the closing > date has long-since passed. Thank you for reminding. Proposal 1 is passed 9 vs 1. Proposal 2 and 3 is declined 1 vs 7 and 1 vs 6. Lazy deletion is design bug fix. This issue cannot be solved without delayed deletion due to technical reason of current web technology. This also involves session security. Current implementation allows attackers to exploit stolen session as long as they want also. I'll come back on this issue later. Thank you for voting all! Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#72983) next »