Re: safe_mode and file upload forms

From: Date: Thu, 01 Jan 1970 00:00:00 +0000
Subject: Re: safe_mode and file upload forms
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-16192@lists.php.net to get a copy of this message
> >> > A tempfile as created by a file upload form seems to be > >> > owned by the webserver user and consequently cannot be > >> > accessed under the safe_mode restriction. That makes > >> > file upload pretty much useless under safe_mode. > >> > >> Correct. This has always been so. > > First, I don't get why it's "useless". You can still upload images, > etc. Second, from what I see in safe_mode.c it appears to me that it's > sufficient that directory would be owned by current user (and writable by > webserver - for upload) and safe mode will be satisfied. Am I mistaken? True, but this requires each user to have a separate upload temp dir. By default this is not the case. -Rasmus

« previous php.dev (#16192) next »