Re: safe_mode and file upload forms
| From: | rasmus@php.net | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: safe_mode and file upload forms | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-16192@lists.php.net to get a copy of this message | ||
> >> > A tempfile as created by a file upload form seems to be
> >> > owned by the webserver user and consequently cannot be
> >> > accessed under the safe_mode restriction. That makes
> >> > file upload pretty much useless under safe_mode.
> >>
> >> Correct. This has always been so.
>
> First, I don't get why it's "useless". You can still upload images,
> etc. Second, from what I see in safe_mode.c it appears to me that it's
> sufficient that directory would be owned by current user (and writable by
> webserver - for upload) and safe mode will be satisfied. Am I mistaken?
True, but this requires each user to have a separate upload temp dir. By
default this is not the case.
-Rasmus