Re[2]: [PEAR-DEV] in search for XML-RPC developers/maintainers contact
| From: | anatoly techtonik | Date: | Mon, 29 Aug 2005 09:17:58 +0000 |
| Subject: | Re[2]: [PEAR-DEV] in search for XML-RPC developers/maintainers contact | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39604@lists.php.net to get a copy of this message | ||
||*()*|| [\..konnichi wa, ogenki desu ka, Edgar../]
ES> I am kind of confused. In between I am in contact with Daniel. As for
ES> now, I will deliver him some patches against the current source of
ES> extensions I wrote to the pear xmplrpc package.
ES> Anyway, I am interested in the background of your phrase "Well, it is my
ES> IMHO". What do you mean by that? Would you tell me about it? Are you
ES> actually advising me to use another xmlrpc package out of reasons in
ES> functionality or politics? It would be very kind of you to tell me about it.
Neither problem is too easy not to be too complex. =) There are three
aspects (in the order of importance):
1. My personal feelings about working with Daniel with this package
and PEAR politics. PEAR doesn't mean quality even if it is said in
manual. In general you don't feel like patching third-party lib you're
supposed to get ready for your projects and visiting bugtracker
too often.
2. Speed and design (no stats, sorry, only code estimation - that's why it
is second). I'm pretty sure there are better libraries than PEAR's XML-RPC
and word PEAR should not deny you from trying another alternatives.
Functionality is probably the same as in other libraries, but
3. A lot of troubles with this package in the past even with lead developer
Dan, who potentially should knew the package weaknesses, but didn't do
anything to close them without third-party patch submissions. For the last
year many PHP products removed support for XML-RPC because of major security
flaws. These include WordPress, Drupal and to my surprise even Mozilla site
was hacked thanks to this bug.
I don't think that the person, who took responsibility for the package in
this way deserves community support. That's my personal opinion.
ES> Thank you very much..
ES> Edgar Soldin
ES> --
>>Hello Edgar,
>>
>>From Monday, August 22, 2005, 11:38:07 AM, you wrote:
>>
>>ES> i am looking for the current maintainers/developers of the pear XML-RPC
>>ES> API. I already wrote to the email addresses mentioned in the source code
>>ES> and also on the pear website. All I received wasn a note from Edd
>>ES> Dumbill, that I might join the mailinglist phpxmlrpc@lists.usefulinc.com
>>ES> for contact, but nothing seems to go on in there. Please would anybody
>>ES> point me a direction please.
>>
>>Well, it is my IMHO, but you will get more feedback if you'll contact
>>actual developers of XML-RPC for PHP at
>>http://phpxmlrpc.sourceforge.net
>>If you need exactly PEARified version - try to ping Daniel Convissor
>>from package "developers".
>>
>>And also you may want to switch to another XML-RPC for PHP protocol
>>implementation (such as icutio's). While phpxmlrpc is most compatible
>>library in terms of API, it's site version is still with PHP3 support
>>may be little bit slower, so before 2.0 version is released you can
>>try some other XML_RPC libraries - links available from
>>http://www.xmlrpc.com/directory/1568/implementations
>>
>>Why am I telling such a bad things about PEAR's XML-RPC? Two major bugs were
>>successfully exploited because PEAR's XML-RPC package "was too important to
>>let other developers to take part". One of "other developers" was me. :p
>>
>>P.S. The qustion to PEAR developers. What's the difference of maintainer,
>>author and lead developer? Is it reflected in package DTD?
>>
>>t
>>
>>
WBR.techtonik
--
(B)uilding, (A)ntenna, (S)pan and (E)arth
* terminal velocity - 54m/s, 305m *