Re: [RFC] [FINAL DISCUSSION] Script only include/require
| From: | Pádraic Brady | Date: | Sat, 21 Feb 2015 08:18:45 +0000 |
| Subject: | Re: [RFC] [FINAL DISCUSSION] Script only include/require | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-83382@lists.php.net to get a copy of this message | ||
Does this have any impact on allow_url_include or has that setting
been retained?
Yes, folk do indeed try to do this, for example hitting up Google:
http://www.quora.com/Why-do-include-and-require_once-not-work-with-remote-files
Paddy
On 21 February 2015 at 01:06, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> Hi all,
>
> I think this will be the final discussion before vote.
> This RFC is to make PHP stronger against script inclusion attacks just like
> other languages.
>
> https://wiki.php.net/rfc/script_only_include
>
> I hope everyone will like this proposal.
> Thank you all who have participated to discussions.
>
> Those who are not involved, this is the time to check this RFC.
>
> Thank you.
>
> --
> Yasuo Ohgaki
> yohgaki@ohgaki.net
--
--
Pádraic Brady
http://blog.astrumfutura.com
http://www.survivethedeepend.com
Zend Framework Community Review Team
Zend Framework PHP-FIG Representative