Re: [RFC][DISCUSSION] Introduce scrpt_path
| From: | Yasuo Ohgaki | Date: | Fri, 06 Feb 2015 19:11:56 +0000 |
| Subject: | Re: [RFC][DISCUSSION] Introduce scrpt_path | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-82062@lists.php.net to get a copy of this message | ||
Hi Leigh,
On Sat, Feb 7, 2015 at 3:46 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
>
>>
>> I think this is a better solution than script{,_once}. I definitely
>> prefer it over the previous RFC
>
>
> I thought script()/script_once() is enough, but it's not.
> There are modules uses custom script loaders, including phar. Those loader
> may do whatever they want, therefore detecting/deciding file type (i.e.
> PHP script)
> by file content is wrong.
>
If parser state is used, script() solution would work and may remove
script_path.
Then it's possible try to read files as PHP script by require() excluding
upload_path/open_basedir/OS restriction. I think this is acceptable.
Please note that OS solution does not help to prevent PHP from reading
uploaded
script.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net