Re: Solution for session_regenerate_id() issues
| From: | Yasuo Ohgaki | Date: | Wed, 19 Mar 2014 10:28:32 +0000 |
| Subject: | Re: Solution for session_regenerate_id() issues | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-73301@lists.php.net to get a copy of this message | ||
Hi Ferenc,
On Wed, Mar 19, 2014 at 7:12 PM, Ferenc Kovacs <tyra3l@gmail.com> wrote:
> >
>> > But speaking of sessions and security, I'll mail you privately about
>> > something because I didn't see an option in the bug reporting form to
>> > mark it as a private one.
>> >
>>
>> If you choose "security" bug type, it's hidden.
>>
>
> nope, security bug type only makes it send the bug mail to
> security@php.net, only private bugs are protected from public access.
> that is something really error-prone, so I remember some discussion about
> changing that, and making new security bugs to be private by default, but
> AFAIK we never implemented that.
>
It surprises me.
Thank you for your info.
--
Yasuo Ohgaki
yohgaki@ohgaki.net