Req #39997 [Opn->Wfx]: allow_url_fopen "2.0"

From: Date: Tue, 27 Jul 2021 10:27:20 +0000
Subject: Req #39997 [Opn->Wfx]: allow_url_fopen "2.0"
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235394@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=39997&edit=1

 ID:                 39997
 Updated by:         cmb@php.net
 Reported by:        phpnet at gwaihir dot net
 Summary:            allow_url_fopen "2.0"
-Status:             Open
+Status:             Wont fix
 Type:               Feature/Change Request
 Package:            Streams related
 Operating System:   all?
 PHP Version:        5.2.0
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Since nothing happened here for more than ten years, I assume
there is not much interest in this feature, so I'm closing as
WONTFIX.  If anybody is still interested in having this feature,
please pursue the RFC process[1].

[1] <https://wiki.php.net/rfc/howto>


Previous Comments:
------------------------------------------------------------------------
[2007-01-01 15:55:45] phpnet at gwaihir dot net

I noticed that it's probably more elegant if this "yes, an URL is ok here" be an
option to set in the stream's context.

------------------------------------------------------------------------
[2006-12-31 18:58:45] phpnet at gwaihir dot net

Description:
------------
Securing PHP against accidentally opening a file/stream from a URL instead of the local filesystem
is nice, however allow_url_fopen as it is, is just too limited, it needs an "explicit
only" setting in addition to just "on" or "off".

In most real world situations, one doesn't want to forbid URL opening server wide, but it would
be way nice if it didn't happen by accidental security oversight. So, what I'd really want
is a setting that allows URL fopen only if I somehow explicitly tell the function I am using that it
should expect a URL.

[Similar concerns are voiced in the responses here: http://bugs.php.net/bug.php?id=28684 The poster is
asking for a different feature though, so continued this seperate request.]

Reproduce code:
---------------
Would go something like this:

PHP.ini:
allow_url_fopen = explicit

Script:
//mode 'u' allows me to open from a URL

fopen(http://example.org/somefile.txt, 'ua+');
//-> should work fine

fopen(http://example.org/somefile.txt, 'a+');
//-> should give a "not allowed" error

Similar ought to go for all functions capable of URL opening, of course. A default of
allow_url_fopen = On still maintains backwards compatibility.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=39997&edit=1


Thread (3 messages)

« previous php.bugs (#235394) next »