Req #43535 [Fbk->NoF]: parse_ini_file('http://example.com/some.ini') and allow_url_include=off
| From: | php-bugs at lists dot php dot net | Date: | Sun, 31 May 2015 04:22:18 +0000 |
| Subject: | Req #43535 [Fbk->NoF]: parse_ini_file('http://example.com/some.ini') and allow_url_include=off | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193023@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=43535&edit=1
ID: 43535
Updated by: php-bugs@lists.php.net
Reported by: sskaje at gmail dot com
Summary: parse_ini_file('http://example.com/some.ini') and
allow_url_include=off
-Status: Feedback
+Status: No Feedback
Type: Feature/Change Request
Package: PHP options/info functions
Operating System: *
PHP Version: 5.2.5
Assigned To: cmb
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2015-05-17 19:49:56] cmb@php.net
Since PHP 5.3.0 there is parse_ini_string(), so you could do:
parse_ini_string(file_get_contents('...'));
Isn't that sufficiently convenient?
------------------------------------------------------------------------
[2009-02-02 16:49:14] sskaje at gmail dot com
[2 Feb 4:41pm UTC] stefan dot walk+php at gmail dot com
I don't see how checking for allow_url_fopen instead of
allow_url_include is a big change ...
ya, stefan, its not a big change, but as you know, all_url_include is recommended to be Off to avoid
RFI, if you need to parse an ini file on a remote server without allow_url_include ON, you have to
download it before parsing it. So, use allow_url_fopen would bring more convinience than
allow_url_include
------------------------------------------------------------------------
[2009-02-02 16:41:16] stefan dot walk+php at gmail dot com
I don't see how checking for allow_url_fopen instead of
allow_url_include is a big change ...
------------------------------------------------------------------------
[2007-12-12 10:12:07] jani@php.net
This requires changes too big for a bugfix (this is more like a new feature as such) so most likely
this will be in PHP 5.3.0 at earliest.
------------------------------------------------------------------------
[2007-12-11 10:01:08] sskaje at gmail dot com
There is a ini file on a http server which has something i need on it.
so i tried to use parse_ini_file() to get the content and parse it.
i set teh 'allow_url_include' Off due to security issue, but i got an error which said
that i must turn it On
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=43535
--
Edit this bug report at https://bugs.php.net/bug.php?id=43535&edit=1