Re: filtered unserialise() - results

From: Date: Fri, 28 Nov 2014 23:03:12 +0000
Subject: Re: filtered unserialise() - results
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-79299@lists.php.net to get a copy of this message
Hi! > Sorry, I missed this thread back when you posted. > Personally I'm a bit hesitant about this change. > Do we already have something additional/upcoming features which could be > a good fit to lump together with allowed_classes? There was talk about limiting depth or breadth to prevent hash DoS attacks, etc. While I myself do not plan to work on it in near future, after some though I decided it does not hurt to provide this opportunity. The added benefit is, given no named parameters syntax yet, this is a good way to introduce people reading the code to the meaning of the feature - ["allowed_classes" => ...] would be pretty obvious about what this does. -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#79299) next »