filtered unserialise() - results
| From: | Stanislav Malyshev | Date: | Tue, 18 Nov 2014 20:34:16 +0000 |
| Subject: | filtered unserialise() - results | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-78957@lists.php.net to get a copy of this message | ||
Hi!
The vote for https://wiki.php.net/rfc/secure_unserialize
has been
completed (actually, should be last week but I was busy, sorry for the
delay) and the RFC is accepted 17 votes for to 6 votes against.
Now, there were proposals to amend this RFC slightly to make the
additional parameter an option array - with sole option currently being
accepted classes list for now - in order to allow future extensibility.
I am somewhat undecided on this option, but rather than make a new vote
for a small implementation change, I want to make an informal poll -
*if* I decide to make it an option array - would anyone strongly oppose
to it, and if so, why?
Note that it is not a vote either way - rather, I'd like to hear if
somebody has an argument against doing this (I've already heard
arguments for it). So if you oppose it, please tell the reasons why. I
have some (which I previously posted on the list) but I'd like to hear
from others too.
Thanks,
Stas