RE : [PHP-DEV] potential solution to user streams + allow_url_include=off
| From: | P) | Date: | Fri, 18 May 2007 17:44:03 +0000 |
| Subject: | RE : [PHP-DEV] potential solution to user streams + allow_url_include=off | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-29521@lists.php.net to get a copy of this message | ||
> From: Ilia Alshanetsky [mailto:ilia@prohost.org]
> I don't think this is a good idea. If you need to access external
> data use fsockopen or stream code or even cURL. Creating
> filters just to add bypasses for them seems silly to me.
If I understand well, the goal here is not to mark remote stream wrappers as local and, thus, bypass
remote protection. The goal is to be able to mark intrinsically-local stream wrappers as local. The
primary clients for this feature are PHP_Archive & PHK. Both don't have anything to do
with remote access, but there is no way to implement them without a stream wrapper.
It is not a question of bypassing filters as the default behavior remains the same. It is just the
possibility to control the filter from a secure place (if we don't consider the code to be
secure, we can restart the whole discussion).
The important point in Greg's proposal is that it does not allow to mark an internal remote
stream as local.
Regards
Francois