Re: Suppressing Exceptions in xarSecConfirmAuthKey()

Marcel van der Boom <[email protected]> Thu, 12 Mar 2009 13:00:25 +0100
Newsgroups gmane.comp.cms.xaraya.devel
Message-ID <[email protected]>
With PHP5 now allowed/default (?), perhaps that RFC-54 is worth  
considering for merging in?

marcel

On 11 mrt 2009, at 18:53, Hb wrote:

> After committing the change
>
> http://mt.xaraya.com/revision/info/d45198a0da4983ec3b2a593db1731951814d6f1d
>
> Marc posted in xaraya.mt-notices:
>
>> It's really none of my business, but this doesn't seem like a  
>> particularly
>> good idea. It seems to subvert the purpose of the  
>> xarSecConfirmAuthKey()
>> function. Does it make sense to change the API for this?
>
> Thanks for your answer. Kris described a scenario where a false  
> returned from
> the function is better than an exception.
>
> We thought that this change does not affect security. And I still  
> can't get it
> why this change does harm something.
> _______________________________________________
> Xaraya_devel mailing list
> [email protected]
> http://xaraya.com/mailman/listinfo/xaraya_devel

-- 
Marcel van der Boom  -- http://hsdev.com/mvdb.vcf
HS-Development BV    -- http://www.hsdev.com
So! web applications -- http://make-it-so.info
Cobra Replica build  -- http://cobra.mrblog.nl

_______________________________________________
Xaraya_devel mailing list
[email protected]
http://xaraya.com/mailman/listinfo/xaraya_devel