note 24173 added to function.popen
| From: | ajv-php at erkle dot org | Date: | Thu, 08 Aug 2002 15:02:34 +0000 |
| Subject: | note 24173 added to function.popen | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-34531@lists.php.net to get a copy of this message | ||
I noticed that some of the examples above seem to advocate passing unencrypted data to gpg via the
pipe shell escape, in the absence of a bi-directional popen (on some OSes).
The approach I've taken is similar to:
$prefix = 'example';
$command = '/usr/local/bin/gpg --encrypt --armor --no-tty --batch --no-secmem-warning
--recipient "joe.soap@example.com"';
$tmpfile = tempnam('/tmp', $prefix);
$pipe = popen("$command 2>&1 >$tmpfile", 'w');
if (!$pipe) {
unlink($tmpfile);
} else {
fwrite($pipe, $plaintxt, strlen($plaintxt));
pclose($pipe);
$fd = fopen($tmpfile, "rb");
$output = fread($fd, filesize($tmpfile));
fclose($fd);
unlink($tmpfile);
}
return $output;
This means that unencrypted information is not passed via a (potentially readable) shell command,
and only encrypted information gets stored on disc.
--
http://www.php.net/manual/en/function.popen.php
http://master.php.net/manage/user-notes.php?action=edit+24173
http://master.php.net/manage/user-notes.php?action=delete+24173
http://master.php.net/manage/user-notes.php?action=reject+24173