Doc #74634 [Csd]: read_exif_data() documented as not taking URLs but allows URLs

From: Date: Tue, 22 Aug 2017 23:35:18 +0000
Subject: Doc #74634 [Csd]: read_exif_data() documented as not taking URLs but allows URLs
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-14919@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74634&edit=1 ID: 74634 User updated by: rskansing at gmail dot com Reported by: rskansing at gmail dot com Summary: read_exif_data() documented as not taking URLs but allows URLs Status: Closed Type: Documentation Problem Package: EXIF related Operating System: Linux PHP Version: 7.1.5 Assigned To: kalle Block user comment: N Private report: N New Comment: Ah okay thanks. I was not sure how the security mark worked Previous Comments: ------------------------------------------------------------------------ [2017-08-22 23:17:59] kalle@php.net I removed the security flag as its a fairly common security issue, nothing secret about it here (issues marked as security are hidden on our bug tracker) ------------------------------------------------------------------------ [2017-08-22 22:54:28] rskansing at gmail dot com > The OP claims that the failure to > explicitly document that the function supports general URL > wrappers, can cause developers to write vulnerable code, which > *might* be the case (I cannot assess that, though). If it was only the lack of mentioning It wouldnt be a issue. What makes it a minor issue is that it explicitly said the opposite. "This cannot be an URL." ------------------------------------------------------------------------ [2017-08-22 22:41:45] rskansing at gmail dot com I am not sure why the security mark was removed on this issue? a developer could previously have used this method in a unsafe way due to the need for further validation/sanitization of input before passing it toe the method compared to what the doc previously said. ------------------------------------------------------------------------ [2017-08-22 22:13:49] cmb@php.net > It was me who was not entirely good at documenting this behavior > I implemented in 7.2, […] Actually, this ticket is not about the new feature that exif_read_data accepts a stream, but rather about the long-standing feature that the function accepts not only filenames (in the strict sense), but also general URL wrappers (such as http://example.com/foo?bar). The OP claims that the failure to explicitly document that the function supports general URL wrappers, can cause developers to write vulnerable code, which *might* be the case (I cannot assess that, though). ------------------------------------------------------------------------ [2017-08-22 17:12:25] kalle@php.net It was me who was not entirely good at documenting this behavior I implemented in 7.2, I blame my long time absence from working with the docs. The exif extension supports streams like other functions that support streams in PHP do, in the same way. Any value passed should always be validated like anything else :) Thanks Christoph for fixing this, didn't see it myself as it was wrongly labeled as a security issue. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=74634 -- Edit this bug report at https://bugs.php.net/bug.php?id=74634&edit=1

« previous php.doc.bugs (#14919) next »