Re: Re: PHP-4.0.7RC1
| From: | Hellekin O. Wolf | Date: | Fri, 17 Aug 2001 16:45:22 +0000 |
| Subject: | Re: Re: PHP-4.0.7RC1 | ||
| References: | 1 | Groups: | php.dev php.qa |
| Request: | Send a blank email to php-dev+get-63543@lists.php.net to get a copy of this message | ||
At 19:16 17/08/2001 +0300, Stanislav Malyshev wrote:
ZS>> While we're at it, I think that we should also take another ZS>> recommendation from the advisory that brought this mess upon us ZS>> - and turn URL fopens off by default. Well, generally I personally would even go further and make two functions - one for file-only fopen (about 90% of fopen usage?) and another which would open everything and the kitchen://sink. Or make some switch, etc. - configuration option doesn't seem to me fit here, it's not per-server but per-script property if you want URL fopens or not.*** Consider a mutli-user environment, like an ISP, where many users can script on the same server. In that case, we need a system-wide configuration flag. However, I agree with you that some cases may require having allow_url_fopen On while preventing most of the others from using it. I think that case is not depending on PHP but rather on a correctly implemented httpd server. hellekin