Re: filtered unserialise() - results
| From: | Stanislav Malyshev | Date: | Fri, 28 Nov 2014 23:03:12 +0000 |
| Subject: | Re: filtered unserialise() - results | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-79299@lists.php.net to get a copy of this message | ||
Hi!
> Sorry, I missed this thread back when you posted.
> Personally I'm a bit hesitant about this change.
> Do we already have something additional/upcoming features which could be
> a good fit to lump together with allowed_classes?
There was talk about limiting depth or breadth to prevent hash DoS
attacks, etc. While I myself do not plan to work on it in near future,
after some though I decided it does not hurt to provide this
opportunity. The added benefit is, given no named parameters syntax yet,
this is a good way to introduce people reading the code to the meaning
of the feature - ["allowed_classes" => ...] would be pretty obvious
about what this does.
--
Stas Malyshev
smalyshev@gmail.com