Re: Re: alternative to the fopen() hack in autoloaders

From: Date: Tue, 10 Nov 2009 19:56:57 +0000
Subject: Re: Re: alternative to the fopen() hack in autoloaders
References: 1 2 3  Groups: php.internals php.internals 
Request: Send a blank email to internals+get-46008@lists.php.net to get a copy of this message
Stanislav Malyshev wrote: > Hi! > >> Alternatively include() could be extended to allow resources, so the >> above would turn info >> >> if ($fp = @fopen($file, 'r', true)) { >> include($fp); >> fclose($fp); >> } > > This would break security distinction between file ops and include ops, > when URLs are allowed for open but not include. > Not really - the wrapper used to open the file pointer is stored in the resource, so we can just check it against the same restrictions we would for static urls. I think this idea deserves another look. Greg

« previous php.internals (#46008) next »