note 24173 modified in function.popen by danbrown
| From: | danbrown@php.net | Date: | Mon, 02 Mar 2009 13:41:27 +0000 |
| Subject: | note 24173 modified in function.popen by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-151338@lists.php.net to get a copy of this message | ||
I noticed that some of the examples above seem to advocate passing unencrypted data to gpg via the
pipe shell escape, in the absence of a bi-directional popen (on some OSes).
The approach I've taken is similar to:
<?php
$prefix = 'example';
$command = '/usr/local/bin/gpg --encrypt --armor --no-tty --batch --no-secmem-warning
--recipient "joe.soap@example.com"';
$tmpfile = tempnam('/tmp', $prefix);
$pipe = popen("$command 2>&1 >$tmpfile", 'w');
if (!$pipe) {
unlink($tmpfile);
} else {
fwrite($pipe, $plaintxt, strlen($plaintxt));
pclose($pipe);
$fd = fopen($tmpfile, "rb");
$output = fread($fd, filesize($tmpfile));
fclose($fd);
unlink($tmpfile);
}
return $output;
?>
This means that unencrypted information is not passed via a (potentially readable) shell command,
and only encrypted information gets stored on disc.
--was--
I noticed that some of the examples above seem to advocate passing unencrypted data to gpg via the
pipe shell escape, in the absence of a bi-directional popen (on some OSes).
The approach I've taken is similar to:
$prefix = 'example';
$command = '/usr/local/bin/gpg --encrypt --armor --no-tty --batch --no-secmem-warning
--recipient "joe.soap@example.com"';
$tmpfile = tempnam('/tmp', $prefix);
$pipe = popen("$command 2>&1 >$tmpfile", 'w');
if (!$pipe) {
unlink($tmpfile);
} else {
fwrite($pipe, $plaintxt, strlen($plaintxt));
pclose($pipe);
$fd = fopen($tmpfile, "rb");
$output = fread($fd, filesize($tmpfile));
fclose($fd);
unlink($tmpfile);
}
return $output;
This means that unencrypted information is not passed via a (potentially readable) shell command,
and only encrypted information gets stored on disc.
http://php.net/manual/en/function.popen.php