Re: potential solution to user streams + allow_url_include=off
| From: | Stanislav Malyshev | Date: | Fri, 18 May 2007 18:32:25 +0000 |
| Subject: | Re: potential solution to user streams + allow_url_include=off | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-29525@lists.php.net to get a copy of this message | ||
oh, and I forgot another thing:
5. Have some function like stream_is_remote() which could check URL for remote-ness,
so that the responsible stream wrapped would not rely on fopen erroring out.
I couldn't locate such function, so if it isn't there it should be added.
I think the problem could be solved this way: 0. allow_url_include and allow_url_fopen renamed to allow_remote_include and allow_remote_fopen (not really necessary, just much cleaner, if you don't like it, ignore it for now). 1. By default, allow_remote_inclue=0, allow_remote_fopen=1 2. Stream can be of three types - remote, local and user/local. 3. User streams can be declared when registered as either remote or user/local, remote being the default. 4. When operation on user/local stream is run, allow_remote_fopen is disabled if allow_remote_include was disabled.-- Stanislav Malyshev, Zend Products Engineer stas@zend.com http://www.zend.com/