Doc #66677 [Com]: CURLOPT_SAFE_UPLOAD missing from curl_setopt docs
| From: | cmbecker69 at gmx dot de | Date: | Thu, 08 Jan 2015 19:20:21 +0000 |
| Subject: | Doc #66677 [Com]: CURLOPT_SAFE_UPLOAD missing from curl_setopt docs | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-11842@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66677&edit=1
ID: 66677
Comment by: cmbecker69 at gmx dot de
Reported by: steffen dot weber at gmail dot com
Summary: CURLOPT_SAFE_UPLOAD missing from curl_setopt docs
Status: Open
Type: Documentation Problem
Package: cURL related
Operating System: Linux
PHP Version: 5.5.9
Block user comment: N
Private report: N
New Comment:
The documentation has been updated accordingly, so the report can
be closed.
Previous Comments:
------------------------------------------------------------------------
[2014-02-09 09:58:40] steffen dot weber at gmail dot com
Description:
------------
In PHP 5.5 there is a new cURL option "CURLOPT_SAFE_UPLOAD" (see https://wiki.php.net/rfc/curl-file-upload) that
is missing from the documentation of curl_setopt (http://www.php.net/function.curl-setopt).
This option is relevant for security: Unless you enable this option anyone who controls the payload
in "curl_setopt($curl, CURLOPT_POSTFIELDS, $payload)" can send arbitrary local files.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66677&edit=1