Re: curl_init() is bypassing safe_mode & open_basedir restrictions

From: Date: Fri, 29 Oct 2004 15:24:00 +0000
Subject: Re: curl_init() is bypassing safe_mode & open_basedir restrictions
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-13594@lists.php.net to get a copy of this message
On Fri, 29 Oct 2004, Klaus Reimer wrote: > Sterling Hughes wrote: > > no.... curl does not need to respect php's safemode, adding such > > checks at this level is wrong. people who compile curl, can do so > > without local file access, and this will solve their problem. > > What about people who use precompiled packages like the Debian packages? > They don't have a "special" Curl for PHP. The curl debian package will > never "disable" file-support just because it breaks a feature of PHP. So > Debian users can't use safemode then if they need the curl extension and > if they don't want (or don't know how) to compile the stuff. Safe mode is for people who are running shared servers and want to wall off areas. If you're doing this, you should be willing and able to configure programs if necessary. I don't mind making ISP sys admins configure cURL with a special flag, nor do I think it's too onerous a burden. -adam -- adam@trachtenberg.com author of o'reilly's "upgrading to php 5" and "php cookbook" avoid the holiday rush, buy your copies today!

« previous php.internals (#13594) next »