Re: Session: deprecating create_sid() method and add createSid()?
| From: | Andrey Andreev | Date: | Mon, 17 Mar 2014 21:59:51 +0000 |
| Subject: | Re: Session: deprecating create_sid() method and add createSid()? | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-73247@lists.php.net to get a copy of this message | ||
Hi,
On Mon, Mar 17, 2014 at 11:15 PM, Pierre Joye <pierre.php@gmail.com> wrote:
> hi,
>
> On Mon, Mar 17, 2014 at 10:09 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
>
> For one, I appreciate the effort that both of you put on the session management.
>
> It seems that you are somehow alone to discuss this issue and slightly
> in circle right now.
>
> I would suggest two steps:
>
> - sit down together for a chat and get your stuff together. It will by
> far more efficient than mails
>
> - write one or more RFCs to fix what should be fixed, how and why (see
> next point :)
>
> - provide more info about the actual critical security impact that
> could be fixed by the changes
> as of now, I failed to see any CVE related to what you are referring to
We'll surely do that.
In fact, I was just about to write Yasuo a private mail about some
security issues, because I didn't find an option to report a bug and
make it hidden. Is there such an option, or does the CVE assignment
process allow that? (I'm not familiar with it)
Cheers,
Andrey.