RE: [PHP-DEV] Re: Serializing exceptions

From: Date: Fri, 31 Jul 2015 20:55:14 +0000
Subject: RE: [PHP-DEV] Re: Serializing exceptions
References: 1 2 3 4 5 6 7 8  Groups: php.internals 
Request: Send a blank email to internals+get-87459@lists.php.net to get a copy of this message
Hi Stas, > -----Original Message----- > From: Stanislav Malyshev [mailto:smalyshev@gmail.com] > Sent: Tuesday, July 28, 2015 10:51 PM > To: Marco Pivetta <ocramius@gmail.com>; Rowan Collins > <rowan.collins@gmail.com> > Cc: Nikita Popov <nikita.ppv@gmail.com>; PHP Internals List > <internals@lists.php.net> > Subject: Re: [PHP-DEV] Re: Serializing exceptions > > Hi! > > > New BC breaks in Beta? > > Why not? What's the problem with it? Beta is to identify issues with current > code, serialized exceptions is an issue (as in, they don't work and lead to security > problems and generally pointless). Dragging this known problem around for > years makes no sense. I was looking through and seems that situation is not that bad. Reading http://fabien.potencier.org/php-serialization-stack-traces-and-exceptions..html it might be not that meaningful to break symphony. Having upset users is logic as long as we don't offer a solution, while the functionality itself seems to make sense. And after all serialization looks useful in some cases (logging at least). Maybe we should go more fine tuning way, maybe ignoring the thing that cannot be serialized. Say, serializing only a white list in this case? Regards Anatol

« previous php.internals (#87459) next »