[PATCH] potential solution to user streams + allow_url_include=off

From: Date: Wed, 30 May 2007 00:16:30 +0000
Subject: [PATCH] potential solution to user streams + allow_url_include=off
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-29917@lists.php.net to get a copy of this message
According to the plan below, attached is the patch that restricts user streams from executing dangerous operations inside include context. Please comment. >>> I think the problem could be solved this way: >>> 0. allow_url_include and allow_url_fopen renamed to >>> allow_remote_include and allow_remote_fopen (not really necessary, >>> just much cleaner, if you don't like it, ignore it for now). >>> 1. By default, allow_remote_inclue=0, allow_remote_fopen=1 >>> 2. Stream can be of three types - remote, local and user/local. >>> 3. User streams can be declared when registered as either remote or >>> user/local, remote being the default. >>> 4. When operation on user/local stream is run, allow_remote_fopen is >>> disabled if allow_remote_include was disabled. -- Stanislav Malyshev, Zend Products Engineer stas@zend.com http://www.zend.com/

« previous php.internals (#29917) next »