Re: curl_init() is bypassing safe_mode & open_basedir restrictions
| From: | Derick Rethans | Date: | Fri, 29 Oct 2004 16:55:06 +0000 |
| Subject: | Re: curl_init() is bypassing safe_mode & open_basedir restrictions | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-13597@lists.php.net to get a copy of this message | ||
On Fri, 29 Oct 2004, Adam Maccabee Trachtenberg wrote:
> On Fri, 29 Oct 2004, Klaus Reimer wrote:
>
> > Sterling Hughes wrote:
> > > no.... curl does not need to respect php's safemode, adding such
> > > checks at this level is wrong. people who compile curl, can do so
> > > without local file access, and this will solve their problem.
> >
> > What about people who use precompiled packages like the Debian packages?
> > They don't have a "special" Curl for PHP. The curl debian package will
> > never "disable" file-support just because it breaks a feature of PHP. So
> > Debian users can't use safemode then if they need the curl extension and
> > if they don't want (or don't know how) to compile the stuff.
>
> Safe mode is for people who are running shared servers and want to
> wall off areas. If you're doing this, you should be willing and able
> to configure programs if necessary. I don't mind making ISP sys admins
> configure cURL with a special flag, nor do I think it's too onerous a burden.
Exactly!
Derick
--
Derick Rethans
http://derickrethans.nl | http://ez.no | http://xdebug.org