[deprecation] Deprecate AddSensitiveParameterAttributeRector - #8337
Merged
TomasVotruba merged 1 commit intoAug 10, 2026
Conversation
…hing parameters by name is vague and risky
TomasVotruba
enabled auto-merge (squash)
August 10, 2026 17:28
TomasVotruba
deleted the
deprecate-sensitive-parameter-attribute-rector
branch
August 10, 2026 17:29
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The rule depends on a user-provided list of variable names and adds
#[\SensitiveParameter]to every parameter that matches by name. Name matching is vague and risky: the same name can hold a non-sensitive value in another context, and the attribute silently hides the argument from stack traces anddebug_backtrace().Marking a parameter as sensitive is a per-case security decision, not a bulk rename. Add the attribute manually where it belongs.
The intended change:
class SomeClass { - public function run(string $password) + public function run(#[\SensitiveParameter] string $password) { } }...but the same config also hits places where it only hurts:
class PasswordPolicy { - public function describe(string $password): string + public function describe(#[\SensitiveParameter] string $password): string { // $password here is a policy name, not a secret, // and is now hidden from every stack trace } }The rule now implements
DeprecatedInterfaceand throws inrefactor(), same as the other deprecated rules. Tests and fixtures are removed; the rule was not part of any set.