Re: Re: alternative to the fopen() hack in autoloaders
| From: | Greg Beaver | Date: | Tue, 10 Nov 2009 19:56:57 +0000 |
| Subject: | Re: Re: alternative to the fopen() hack in autoloaders | ||
| References: | 1 2 3 | Groups: | php.internals php.internals |
| Request: | Send a blank email to internals+get-46008@lists.php.net to get a copy of this message | ||
Stanislav Malyshev wrote:
> Hi!
>
>> Alternatively include() could be extended to allow resources, so the
>> above would turn info
>>
>> if ($fp = @fopen($file, 'r', true)) {
>> include($fp);
>> fclose($fp);
>> }
>
> This would break security distinction between file ops and include ops,
> when URLs are allowed for open but not include.
>
Not really - the wrapper used to open the file pointer is stored in the
resource, so we can just check it against the same restrictions we would
for static urls. I think this idea deserves another look.
Greg