Re: [RFC][VOTE] Session ID without hashing - Reopened
| From: | Davey Shafik | Date: | Sun, 24 Jul 2016 05:37:17 +0000 |
| Subject: | Re: [RFC][VOTE] Session ID without hashing - Reopened | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94666@lists.php.net to get a copy of this message | ||
Yasuo,
It didn't actually reopen, and just setting closed to false, it kept the
original votes. So I added a second vote below. Bonus: the original is also
preserved.
Hope that's OK.
- Davey
On Sat, Jul 23, 2016 at 9:50 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> Hi all,
>
> Due to a defect in the RFC, vote is reopened for a week. Removed lines
> are indicated by <del></del>. No additional lines nor modifications
> other than removed lines for session.use_strict_mode change.
> Sorry for the confusion!
>
> ============
>
> Currently session module uses obsolete MD5 for session ID. With
> CSPRNG, hashing is redundant and needless. It adds hash module
> dependency and inefficient (There is no reason to use hash for CSPRNG
> generated bytes).
>
> This proposal cleans up session code by removing hash.
>
> https://wiki.php.net/rfc/session-id-without-hashing
>
> I set vote requires 2/3 support.
> Please describe the reason why when you against this RFC. Reasons are
> important for improvements!
>
> Thank you!
>
> --
> Yasuo Ohgaki
> yohgaki@ohgaki.net
>
> --
> PHP Internals - PHP Runtime Development Mailing List
> To unsubscribe, visit: http://www.php.net/unsub.php
>