note 24173 modified in function.popen by danbrown

From: Date: Mon, 02 Mar 2009 13:41:27 +0000
Subject: note 24173 modified in function.popen by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-151338@lists.php.net to get a copy of this message
I noticed that some of the examples above seem to advocate passing unencrypted data to gpg via the pipe shell escape, in the absence of a bi-directional popen (on some OSes). The approach I've taken is similar to: <?php $prefix = 'example'; $command = '/usr/local/bin/gpg --encrypt --armor --no-tty --batch --no-secmem-warning --recipient "joe.soap@example.com"'; $tmpfile = tempnam('/tmp', $prefix); $pipe = popen("$command 2>&1 >$tmpfile", 'w'); if (!$pipe) { unlink($tmpfile); } else { fwrite($pipe, $plaintxt, strlen($plaintxt)); pclose($pipe); $fd = fopen($tmpfile, "rb"); $output = fread($fd, filesize($tmpfile)); fclose($fd); unlink($tmpfile); } return $output; ?> This means that unencrypted information is not passed via a (potentially readable) shell command, and only encrypted information gets stored on disc. --was-- I noticed that some of the examples above seem to advocate passing unencrypted data to gpg via the pipe shell escape, in the absence of a bi-directional popen (on some OSes). The approach I've taken is similar to: $prefix = 'example'; $command = '/usr/local/bin/gpg --encrypt --armor --no-tty --batch --no-secmem-warning --recipient "joe.soap@example.com"'; $tmpfile = tempnam('/tmp', $prefix); $pipe = popen("$command 2>&1 >$tmpfile", 'w'); if (!$pipe) { unlink($tmpfile); } else { fwrite($pipe, $plaintxt, strlen($plaintxt)); pclose($pipe); $fd = fopen($tmpfile, "rb"); $output = fread($fd, filesize($tmpfile)); fclose($fd); unlink($tmpfile); } return $output; This means that unencrypted information is not passed via a (potentially readable) shell command, and only encrypted information gets stored on disc. http://php.net/manual/en/function.popen.php

« previous php.notes (#151338) next »