Re: Re: [RFC][VOTE] Add validation functions to filter module
| From: | Yasuo Ohgaki | Date: | Wed, 17 Aug 2016 00:30:31 +0000 |
| Subject: | Re: Re: [RFC][VOTE] Add validation functions to filter module | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-95249@lists.php.net to get a copy of this message | ||
Hi Pierre,
On Wed, Aug 17, 2016 at 9:19 AM, Pierre Joye <pierre.php@gmail.com> wrote:
> On Aug 15, 2016 10:36 AM, "Yasuo Ohgaki" <yohgaki@ohgaki.net> wrote:
>
>> I don't mind suspend vote for a while to resolve issues if there
>> should be changes in the RFC. I also don't mind adding missing
>> features, e.g. helpful error messages when exception is disabled, to
>> my todo list. BTW, I'll document basic idea of secure coding and
>> emphasize how it should be done, so misuse would be few.
>
> There is no such thing as suspended vote. The vote has to restart if there
> are changes.
Thank you.
I'll restart vote if I have to make changes, other than more items in
discussion section.
Anyone would change votes if I rename functions to avoid possible
confusions? There is one opinion for better names so far.
It seems either "People misunderstand secure coding" and/or "People consider
validation codes should be in userland fully". (Or "No more additions
for filter module"?)
Although I do think repetitive validations for browser's request
headers/inputs in userland is awfully inefficient, efficiency is not
1st priority of security anyway.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net