Req #36170 [Opn->Wfx]: parse_ini_file control over constants' substitution

From: Date: Mon, 26 Jul 2021 18:45:39 +0000
Subject: Req #36170 [Opn->Wfx]: parse_ini_file control over constants' substitution
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235377@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=36170&edit=1 ID: 36170 Updated by: cmb@php.net Reported by: spam01 at pornel dot net Summary: parse_ini_file control over constants' substitution -Status: Open +Status: Wont fix Type: Feature/Change Request Package: Filesystem function related Operating System: * PHP Version: 5.1.2 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: parse_ini_file() supports the INI_SCANNER_RAW mode for a very long time, and I deem that sufficient for the hopefully rare case where you need to parse user supplied INI files. Previous Comments: ------------------------------------------------------------------------ [2006-01-26 18:01:08] spam01 at pornel dot net Description: ------------ I don't agree with bug Bug #34949 being bogus. It was rejected stating it's programmers' responsibility to check if data can be trusted. However this function doesn't offer such possibility - there is no way to check what data has been substituted. Thus this function is not safe for reading untrusted files. It's not unusual to read and display data structure from untrusted source. You can do that with text files, XML, why not with ini? Instead of originally sugested flag for disabling substitution I suggest adding optional callback function which could be used as security check/filter or provider of custom source of ini constants. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=36170&edit=1

« previous php.bugs (#235377) next »