Re: Re: session_regenerate_id(true) by default

From: Date: Tue, 29 Oct 2013 19:25:08 +0000
Subject: Re: Re: session_regenerate_id(true) by default
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message
Hi Christopher,

On Wed, Oct 30, 2013 at 2:14 AM, Christopher Jones <
[email protected]> wrote:

> If parameter omission is an issue, I think you should update the PHP
> function doc ASAP and explain the problem.
>
> Most E_DEPRECATED messages include the word "deprecated".  I think
> your message could be:
>
>   "Calling session_regenerate_id() without a parameter is
>    deprecated. Passing true is encouraged for better security"
>
> Can you review whether "false" should ever be an allowed value?
>
> The PHP doc could be improved to explain why someone might use true or
> false.
>
> FWIW, the message line in the RFC patch got truncated
>

Thank you!
 I'll fix them soon.

Regards,

--
Yasuo Ohgaki
[email protected]


Thread (20 messages)

« previous php.internals (#69954) next »