Re: Re: allow_url_fopen should be INI_ALL

From: Date: Mon, 27 Jun 2005 07:19:56 +0000
Subject: Re: Re: allow_url_fopen should be INI_ALL
References: 1 2 3 4 5 6 7 8  Groups: php.internals 
Request: Send a blank email to internals+get-16922@lists.php.net to get a copy of this message
Derick Rethans wrote: > On Mon, 27 Jun 2005, Yasuo Ohgaki wrote: > > >>I think most of us can agree following statement >> >>"allow_url_fopen = ON" is dangerous and the feature is not >>useful most of the times. > > > I disagree. With proper filtering, or using non-user-supplied > information there is no problem. I don't have objection to your statement. It could be used safely, but there are many applications that had serious problems even if applications did not require allow_url_fopen to be enabled. I understands one have different opinion to another, so the most acceptable configution for most would be make allow_url_fopen - OFF by default - INI_ALL -- Yasuo Ohgaki

« previous php.internals (#16922) next »