Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork9.7k
Add #[\SensitiveParameter] to $sessionId#49016
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
Uh oh!
There was an error while loading.Please reload this page.
Conversation
carsonbot commentedJan 17, 2023
Hey! I see that this is your first PR. That is great! Welcome! Symfony has acontribution guide which I suggest you to read. In short:
Review the GitHub status checks of your pull request and try to solve the reported issues. If some tests are failing, try to see if they are failing because of this change. When two Symfony core team members approve this change, it will be merged and you will become an official Symfony contributor! I am going to sit back now and wait for the reviews. Cheers! Carsonbot |
GromNaN left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
Very good idea, session ids are indeed sensitive data as stated by owasp:https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html
mfb commentedJan 18, 2023
The suggested code style fix athttps://fabbot.io/patch/symfony/symfony/49016/32c9f28bebe3573431644838db625ef941f5405b/cs.diff looks wrong - I don't think I should remove a blank line just because I added an attribute to the function arguments. Icould not add it in those places, given this is just an abstract class, but seemed helpful for developers to have it there too. |
stof commentedJan 18, 2023
Those blank line removals indeed look like a bug in php-cs-fixer (maybe a fixer is not handling attributes on parameters properly) |
nicolas-grekas commentedJan 19, 2023
Thank you@mfb. |
Uh oh!
There was an error while loading.Please reload this page.
Follow-up to#48274 and#46183