patch to allow file-uploads in safe_mode without user-id fiddleing

From: Date: Mon, 08 Jan 2001 19:07:51 +0000
Subject: patch to allow file-uploads in safe_mode without user-id fiddleing
Groups: php.dev 
Request: Send a blank email to php-dev+get-43435@lists.php.net to get a copy of this message
Index: main/safe_mode.c =================================================================== RCS file: /repository/php4/main/safe_mode.c,v retrieving revision 1.24 diff -u -u -r1.24 safe_mode.c --- main/safe_mode.c 2000/12/16 20:52:43 1.24 +++ main/safe_mode.c 2001/01/08 19:01:25 @@ -121,6 +121,14 @@ if (duid == (uid=php_getuid())) { return 1; } else { + SLS_FETCH(); + + if (SG(rfc1867_uploaded_files)) { + if (zend_hash_exists(SG(rfc1867_uploaded_files),filename,strlen(filename)+1)) { + return 1; + } + } + php_error(E_WARNING, "SAFE MODE Restriction in effect. The script whose uid is %ld is not allowed to access %s owned by uid %ld", uid, filename, duid); return 0; } am i way off or is this something we should allow? explanation: allow access to every rfc1867_uploaded_files in safe_mode even if itÄs not owned by the same UID as the script. tc

« previous php.dev (#43435) next »