30 Jan
2006
30 Jan
'06
4:33 a.m.
I am now convinced that making the PHP filter functionality a separate module is the best way to go. This way, those who need PHP filtering can turn it on explicitly. Help or documentation or disclaimers will state the drawbacks of that. If people want it, it is their choice. So, it is off by default, and has to be turned on manually by the site admin. It has to stay in core, and not be a contrib module. The reason is that this raises its quality, and is under constant scrutiny that is often not the case with contrib. chx pages module is worth exploring two, but Ber's approach addresses the security aspect of the filter.