Re: [RFC] [FINAL DISCUSSION] Script only include/require

From: Date: Sat, 21 Feb 2015 08:18:45 +0000
Subject: Re: [RFC] [FINAL DISCUSSION] Script only include/require
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-83382@lists.php.net to get a copy of this message
Does this have any impact on allow_url_include or has that setting been retained? Yes, folk do indeed try to do this, for example hitting up Google: http://www.quora.com/Why-do-include-and-require_once-not-work-with-remote-files Paddy On 21 February 2015 at 01:06, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > Hi all, > > I think this will be the final discussion before vote. > This RFC is to make PHP stronger against script inclusion attacks just like > other languages. > > https://wiki.php.net/rfc/script_only_include > > I hope everyone will like this proposal. > Thank you all who have participated to discussions. > > Those who are not involved, this is the time to check this RFC. > > Thank you. > > -- > Yasuo Ohgaki > yohgaki@ohgaki.net -- -- Pádraic Brady http://blog.astrumfutura.com http://www.survivethedeepend.com Zend Framework Community Review Team Zend Framework PHP-FIG Representative

« previous php.internals (#83382) next »