Re: [RFC DRAFT] Automatic CSRF Protection

From: Date: Wed, 11 May 2016 05:19:19 +0000
Subject: Re: [RFC DRAFT] Automatic CSRF Protection
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-93199@lists.php.net to get a copy of this message
Hi Pierre, On Wed, May 11, 2016 at 1:12 PM, Pierre Joye <pierre.php@gmail.com> wrote: > The current session code and designs is old, very old. It does not match > today ways to do things. Every time we fix it, I see a band aid fix. Let's rewrite session module someday. In the meantime, I would like to add features to make session management like TCP. We don't have to care about authenticity (CSRF) with TLS/TCP, but web developers must care with TLS/HTTP :( Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#93199) next »