note 51749 added to function.include

From: Date: Sat, 09 Apr 2005 18:21:39 +0000
Subject: note 51749 added to function.include
Groups: php.notes 
Request: Send a blank email to php-notes+get-87762@lists.php.net to get a copy of this message
To expand on marco_ at voxpopuli-forum dot net's and redeye at cs-aktuell dot de's notes, here's a function to securely include files with direct output or a return. <?php /* The DOC_ROOT constant should set on it's own just fine. If you would like to set a sub-directory, just tack it on to the end. For example: define ( 'DOC_ROOT', $_SERVER["DOCUMENT_ROOT"]."/inc_dir" ); define ( 'DOC_ROOT', $_SERVER["DOCUMENT_ROOT"]."/stuff/inc_dir" ); NOTE: Leave the trailing slash off. It shouldn't make a difference mostly, but just in case ;) */ define ( 'DOC_ROOT', $_SERVER["DOCUMENT_ROOT"] ); /* Fill this with all forbidden files. It only requires a filename, not the directory.*/ $badFiles = array ( 'database.inc.php' ); /* Fill this with all forbidden directories. Please provide the absolute path, with DOC_ROOT starting the path. Please see the example already in the array.*/ $badDirs = array ( DOC_ROOT.'/private', ); /** * Provides a secure method of including files. * * @param string $file the file to include * @param bool $return wether or not to output directly or return via output buffering * @return bool|string false on failure, true on success without $return=true, string * with file with $return=true * @author James "necrotic" Logsdon <necrotic at gmail dot com> * @version 1.0 */ function secure_include ( $file, $return = false ) { global $badFiles, $badDirs; if ( !is_array ( $badFiles ) OR !isset ( $badFiles ) ) $badFiles = array(); if ( !is_array ( $badDirs ) OR !isset ( $badDirs ) ) $badDirs = array(); // Get path information $realPath = realpath ( $file ); $dirName = dirname ( $realPath ); $baseName = basename ( $realPath ); if ( !$realPath ) { // The file wasn't found by realpath, so we have a 404. echo '<h1>404 Not Found</h1> We could not find the file you tried to load.'; return false; } else if ( in_array ( $baseName, $badFiles ) OR in_array ( $dirName, $badDirs ) OR !strstr ( $realPath, DOC_ROOT ) ) { // Oh crap! It's a forbidden file! echo '<h1>403 Forbidden</h1> You do not have permission to view this file.'; return false; } else if ( !$return ) { // We're safe, include away! include_once ( $file ); return true; } else { ob_start(); include_once ( $file ); $page = ob_get_contents(); ob_end_clean(); return $page; } } /* * Usage * secure_include ( 'file.txt' ); // returns true if exists, outputs error or file * secure_include ( 'file.txt', true ); // returns the file if exists, outputs error if not or 403 Forbidden */ ?> ---- Manual Page -- http://www.php.net/manual/en/function.include.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+51749 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+51749&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+51749&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+51749&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+51749&report=yes&reason=useless Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+51749&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+51749&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#87762) next »