Re: [RFC DRAFT] Automatic CSRF Protection
| From: | Yasuo Ohgaki | Date: | Wed, 11 May 2016 05:19:19 +0000 |
| Subject: | Re: [RFC DRAFT] Automatic CSRF Protection | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-93199@lists.php.net to get a copy of this message | ||
Hi Pierre,
On Wed, May 11, 2016 at 1:12 PM, Pierre Joye <pierre.php@gmail.com> wrote:
> The current session code and designs is old, very old. It does not match
> today ways to do things. Every time we fix it, I see a band aid fix.
Let's rewrite session module someday.
In the meantime, I would like to add features to make session
management like TCP.
We don't have to care about authenticity (CSRF) with TLS/TCP, but web
developers must care with TLS/HTTP :(
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net