Source: davical Version: 1.0.2-1 Severity: wishlist
Hi. This is perhaps a wontfix, but is it possible to rewrite the parts of Davical using PHP's eval() function to no longer use it? This can be a dangerous function and in suhosin it's even possible to deactivate it. If the above is not possible: Could you maintain a list that one can use with suhosin.executor.eval.whitelist (seet http://www.hardened-php.net/suhosin/configuration.html#suhosin.executor.eval.whitelist ) And if both are not possible: Could you warn somewhere in the documentation that one must not disable eval() (e.g. via suhosin). Perhaps adding a README.suhosin file, that also tells about the suhosin.server.strip = Off requirement would be a good idea. Cheers, Chris. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org