Re: Session: deprecating create_sid() method and add createSid()?

From: Date: Mon, 17 Mar 2014 21:24:12 +0000
Subject: Re: Session: deprecating create_sid() method and add createSid()?
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message
Hi Pierre,

On Tue, Mar 18, 2014 at 6:15 AM, Pierre Joye <[email protected]> wrote:

> For one, I appreciate the effort that both of you put on the session
> management.
>
> It seems that you are somehow alone to discuss this issue and slightly
> in circle right now.
>
> I would suggest two steps:
>
> - sit down together for a chat and get your stuff together. It will by
> far more efficient than mails
>

Sounds good.
I'm not on IRC, which one should I use?


>
> - write one or more RFCs to fix what should be fixed, how and why (see
> next point :)
>

Sure.


>
> - provide more info about the actual critical security impact that
> could be fixed by the changes
>   as of now, I failed to see any CVE related to what you are referring to
>

There wouldn't be CVE as it may be implemented by user land.
I may try to ask MITRE to give me a CVE, though.

Regards,

--
Yasuo Ohgaki
[email protected]


Thread (39 messages)

« previous php.internals (#73237) next »