Hi Lynn

On 1/12/22 9:30 AM, Lynn wrote:
  I was thinking more of a "keep track of the values replaced, and in the
end purge all those values from the end-result" kinda thing.


Thank you for the clarification. This still is not in scope, because I believe that to be harmful, as the parameter redaction will be completely unpredictable.

Consider a sensitive parameter that is of type '?string', i.e. nullable. Now with your proposal, whenever 'null' is passed to this parameter, all 'null's within the stack trace would be hidden, even if they are completely unrelated.

Best regards
Tim Düsterhus
Developer WoltLab GmbH

--

WoltLab GmbH
Nedlitzer Str. 27B
14469 Potsdam

Tel.: +49 331 96784338

duester...@woltlab.com
www.woltlab.com

Managing director:
Marcel Werk

AG Potsdam HRB 26795 P

--
PHP Internals - PHP Runtime Development Mailing List
To unsubscribe, visit: https://www.php.net/unsub.php

Reply via email to