Re: [RFC][VOTE] Add validation functions to filter module

From: Date: Thu, 01 Sep 2016 11:59:24 +0000
Subject: Re: [RFC][VOTE] Add validation functions to filter module
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-95532@lists.php.net to get a copy of this message
Hi Yasuo, > On 31 Aug 2016, at 21:45, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: [...] > Thank you for voting! > The RFC is declined 1 vs 13 > A bit surprised this result. > > I requested the reason of objection, but many of them does not disclose why. [...] > lstrojny (lstrojny) [...] sorry for not chiming in earlier, but I indeed owe you an explanation. I believe making ext/filter a part of PHP created more trouble than it solved, even though I applaud it’s intention. Of course, filtering and validation are necessary essentials of any secure web application. I nevertheless strongly believe validation and filtering must live in userland. Validation and filtering are often very much tied to the domain problem a user of PHP is to solving and the change rate of the application will be higher than the change rate of the language (hopefully). To give a more concrete example: let’s say our problem is we want to validate if a string is a valid domain because our business is registering domains. Nowadays, top level domains are introduced quite often and there is no way PHP could have a nice, up to date whitelist of TLDs all of the time and as a domain registration business it’s impossible for me to wait for the updated whitelist in PHP NEXT. That’s why I believe this is something that belongs to userland so the library that offers (domain) validation can follow a lifecycle that fits the problem it is trying to solve. cu, Lars

Attachment: [application/pgp-signature] Message signed with OpenPGP using GPGMail signature.asc
« previous php.internals (#95532) next »