Req #79541 [Com]: Add ini option to disable URLs in getimagesize
| From: | bugreports at gmail dot com | Date: | Wed, 29 Apr 2020 17:42:28 +0000 |
| Subject: | Req #79541 [Com]: Add ini option to disable URLs in getimagesize | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-226833@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79541&edit=1
ID: 79541
Comment by: bugreports at gmail dot com
Reported by: mail at tomsommer dot dk
Summary: Add ini option to disable URLs in getimagesize
Status: Feedback
Type: Feature/Change Request
Package: GetImageSize related
PHP Version: 7.4.5
Block user comment: N
Private report: N
New Comment:
no, the whole https://www.php.net/manual/en/wrappers.php
stuff is designed in a way that it don#t matter if the path is a physical file or a supported remote
file and there is no sane reason to poke special handling into random function signatures
> as it is often a sign of someone providing bad arguments (url instead of path)
you are responsible to write code with validates input as developer
Previous Comments:
------------------------------------------------------------------------
[2020-04-29 17:42:05] mail at tomsommer dot dk
Should be a separate option than allow_url_fopen
------------------------------------------------------------------------
[2020-04-29 17:42:03] requinix@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.
A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc. If the script requires a
database to demonstrate the issue, please make sure it creates
all necessary tables, stored procedures etc.
Please avoid embedding huge scripts into the report.
Are you passing unvalidated input to getimagesize? If the problem is that someone is giving you a
URL and you don't want them to, then the solution is to make sure that you don't let
someone give you a URL.
------------------------------------------------------------------------
[2020-04-29 17:39:28] mail at tomsommer dot dk
Description:
------------
Would be great to have a php.ini-option to disable the get-URL functionality in getimagesize(), as
it is often a sign of someone providing bad arguments (url instead of path).
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79541&edit=1