Re: [RFC] [VOTE] Filtered unserialize()
| From: | Stas Malyshev | Date: | Mon, 03 Nov 2014 21:33:57 +0000 |
| Subject: | Re: [RFC] [VOTE] Filtered unserialize() | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-78595@lists.php.net to get a copy of this message | ||
Hi!
> Coming late to the discussion. Was there any discussion to make the
> new argument a callback instead? Pass it the fully-qualified class
> name, have it return true (the class should be loaded) or false (the
> class should not be loaded). Deprecate the ˜‰/Ÿ
> ñ¾‘(øf¥unserialize_callback_func
> mechanism at the same time.
That was not discussed. It can be made this way, though it would be more
complicated and have more moving parts, but that's not part of the
present RFC.
--
Stanislav Malyshev, Software Architect
SugarCRM: http://www.sugarcrm.com/