Re: [RFC] [VOTE] Filtered unserialize()
| From: | Leigh | Date: | Mon, 03 Nov 2014 23:04:56 +0000 |
| Subject: | Re: [RFC] [VOTE] Filtered unserialize() | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-78604@lists.php.net to get a copy of this message | ||
On 3 November 2014 21:10, Stas Malyshev <smalyshev@sugarcrm.com> wrote:
> Hi!
>
> I'd like to put to vote my proposal about the filtered unserialize():
>
> https://wiki.php.net/rfc/secure_unserialize
>
> It was discussed a number of times before and I think it is time to have
> a decision on it. If you need any clarifications on the proposal, please
> do not hesitate to ask.
> --
I wonder how often the final parameter will simply be get_declared_classes()
Instead of true/false/array, maybe we could go for int/array and have
constants for "allow anything", "disallow everything", "allow declared
only".