Re: [RFC] [VOTE] Filtered unserialize()
| From: | Andrea Faulds | Date: | Mon, 03 Nov 2014 22:17:31 +0000 |
| Subject: | Re: [RFC] [VOTE] Filtered unserialize() | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-78598@lists.php.net to get a copy of this message | ||
> On 3 Nov 2014, at 21:33, Stas Malyshev <smalyshev@sugarcrm.com> wrote:
>
>> Coming late to the discussion. Was there any discussion to make the
>> new argument a callback instead? Pass it the fully-qualified class
>> name, have it return true (the class should be loaded) or false (the
>> class should not be loaded). Deprecate the
>>
unserialize_callback_func
>> mechanism at the same time.
>
> That was not discussed. It can be made this way, though it would be more
> complicated and have more moving parts, but that's not part of the
> present RFC.
The way the RFC does it doesn’t preclude using a callback, so this could
always be done later.
--
Andrea Faulds
http://ajf.me/