Req #36170 [Opn->Wfx]: parse_ini_file control over constants' substitution
| From: | cmb@php.net | Date: | Mon, 26 Jul 2021 18:45:39 +0000 |
| Subject: | Req #36170 [Opn->Wfx]: parse_ini_file control over constants' substitution | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-235377@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=36170&edit=1
ID: 36170
Updated by: cmb@php.net
Reported by: spam01 at pornel dot net
Summary: parse_ini_file control over constants' substitution
-Status: Open
+Status: Wont fix
Type: Feature/Change Request
Package: Filesystem function related
Operating System: *
PHP Version: 5.1.2
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
parse_ini_file() supports the INI_SCANNER_RAW mode for a very long
time, and I deem that sufficient for the hopefully rare case where
you need to parse user supplied INI files.
Previous Comments:
------------------------------------------------------------------------
[2006-01-26 18:01:08] spam01 at pornel dot net
Description:
------------
I don't agree with bug Bug #34949 being bogus.
It was rejected stating it's programmers' responsibility to check if data can be trusted.
However this function doesn't offer such possibility - there is no way to check what data has
been substituted. Thus this function is not safe for reading untrusted files.
It's not unusual to read and display data structure from untrusted source. You can do that with
text files, XML, why not with ini?
Instead of originally sugested flag for disabling substitution I suggest adding optional callback
function which could be used as security check/filter or provider of custom source of ini constants.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=36170&edit=1