Req #50684 [ReO->Csd]: max_file_uploads can't be changed from .htaccess
Edit report at https://bugs.php.net/bug.php?id=50684&edit=1
ID: 50684
Updated by: phpdocbot@php.net
Reported by: john dot peterson10 at gmail dot com
Summary: max_file_uploads can't be changed from .htaccess
-Status: Re-Opened
+Status: Closed
Type: Feature/Change Request
Package: *General Issues
Operating System: Windows
PHP Version: 7.3
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of aharvey
Revision: http://git.php.net/?p=doc/en.git;a=commit;h=568d68b95ac7a99963076491f4d8f76d6c2733c0
Log: Fix bug #50684 (max_file_uploads can't be changed from .htaccess (or ini_set)) by changing
the documentation to reflect max_file_uploads being PHP_INI_SYSTEM, not PHP_INI_ALL as previously
documented.
Previous Comments:
------------------------------------------------------------------------
[2019-10-10 17:57:54] teo8976 at gmail dot com
> But you are right about .htaccess, I think. We probably should allow this
> setting to be changed there
So why the f*** was and still is this closed??
------------------------------------------------------------------------
[2012-02-17 17:49:05] rasmus@php.net
ini_set would never work because file uploads happen before the PHP script is
executed, so by the time you call ini_set() it would be too late.
But you are right about .htaccess, I think. We probably should allow this setting
to be changed there. It is always a tricky balance when it comes to security-
related settings. In some environments you want to lock down the security-related
settings in a single place and not allow individual users/apps to override these,
and in other environments you want to let users/apps have more rope.
------------------------------------------------------------------------
[2012-02-17 15:52:19] gonssal at gmail dot com
How do you close this bug without adding the posibility of changing the
parameter value through ini_set and .htaccess? This has to be the most retarded
idea a PHP dev has had since the "magic quotes" epic fiasco, breaking lots of
flawlessly and security-proof code working after a PHP version update, without
any warning (not even a Notice).
Also jani@php.net I've seen you answer in 3 different bugs in a way that makes
it seem like this won't be ever addressed. I can understand it was your
"brilliant" idea to implement this, but a bit of humility and acceptance of
errors would be really appreciated.
And sorry if someone is offended by the 'tone' of this message but when you have
to spend 3 days reviewing _ALL_ the projectes using the CMS you developed, in a
lot of different servers because, you know they'll stop working when PHP version
is updated, due to a "great idea" (not really), well your mood goes down real
quick.
------------------------------------------------------------------------
[2010-09-28 21:39:04] guy dot paddock at redbottledesign dot com
Define "can of worms" with regard to this setting.
I'm sorry, but... umm... doesn't allowing sites to override *any* setting
(including memory_limit) have the possibility of bad things happening? And, yet,
we allow that.
It is strange to me how for some reason this one setting that so many people are
now having trouble with is not allowed to be overridden at the reasonable level
of per-site, or per-folder. If people are really concerned about locking-down
the setting on their server, they can use php_admin_value in the INI.
As for me, like the rest of the developers who've encountered this botched
feature, it's getting disabled until it's fixed. I have a rash of users upset
that they can't upload more than 20 pictures per post, and I don't see how
raising that limit to 300 server-wide would be any better.
------------------------------------------------------------------------
[2010-03-05 04:37:39] aharvey@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=50684
--
Edit this bug report at https://bugs.php.net/bug.php?id=50684&edit=1
Thread (6 messages)