Req #43535 [Opn->Fbk]: parse_ini_file('http://example.com/some.ini') and allow_url_include=off
| From: | cmb@php.net | Date: | Sun, 17 May 2015 19:49:56 +0000 |
| Subject: | Req #43535 [Opn->Fbk]: parse_ini_file('http://example.com/some.ini') and allow_url_include=off | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192718@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=43535&edit=1
ID: 43535
Updated by: cmb@php.net
Reported by: sskaje at gmail dot com
Summary: parse_ini_file('http://example.com/some.ini') and
allow_url_include=off
-Status: Open
+Status: Feedback
Type: Feature/Change Request
Package: PHP options/info functions
Operating System: *
PHP Version: 5.2.5
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Since PHP 5.3.0 there is parse_ini_string(), so you could do:
parse_ini_string(file_get_contents('...'));
Isn't that sufficiently convenient?
Previous Comments:
------------------------------------------------------------------------
[2009-02-02 16:49:14] sskaje at gmail dot com
[2 Feb 4:41pm UTC] stefan dot walk+php at gmail dot com
I don't see how checking for allow_url_fopen instead of
allow_url_include is a big change ...
ya, stefan, its not a big change, but as you know, all_url_include is recommended to be Off to avoid
RFI, if you need to parse an ini file on a remote server without allow_url_include ON, you have to
download it before parsing it. So, use allow_url_fopen would bring more convinience than
allow_url_include
------------------------------------------------------------------------
[2009-02-02 16:41:16] stefan dot walk+php at gmail dot com
I don't see how checking for allow_url_fopen instead of
allow_url_include is a big change ...
------------------------------------------------------------------------
[2007-12-12 10:12:07] jani@php.net
This requires changes too big for a bugfix (this is more like a new feature as such) so most likely
this will be in PHP 5.3.0 at earliest.
------------------------------------------------------------------------
[2007-12-11 10:01:08] sskaje at gmail dot com
There is a ini file on a http server which has something i need on it.
so i tried to use parse_ini_file() to get the content and parse it.
i set teh 'allow_url_include' Off due to security issue, but i got an error which said
that i must turn it On
------------------------------------------------------------------------
[2007-12-10 09:58:56] jani@php.net
And what exactly is the problem you have?
Currently the file opening for this function happens exactly how a script is opened and I don't
think there's anything wrong with that.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=43535
--
Edit this bug report at https://bugs.php.net/bug.php?id=43535&edit=1