cvs: pear /HTTP_Upload Upload.php

From: Date: Wed, 28 Nov 2001 17:56:11 +0000
Subject: cvs: pear /HTTP_Upload Upload.php
Groups: php.pear.cvs 
Request: Send a blank email to pear-cvs+get-1426@lists.php.net to get a copy of this message
cox Wed Nov 28 12:56:11 2001 EDT Modified files: /pear/HTTP_Upload Upload.php Log: more phpdoc comments/TODO Index: pear/HTTP_Upload/Upload.php diff -u pear/HTTP_Upload/Upload.php:1.14 pear/HTTP_Upload/Upload.php:1.15 --- pear/HTTP_Upload/Upload.php:1.14 Wed Nov 28 12:46:52 2001 +++ pear/HTTP_Upload/Upload.php Wed Nov 28 12:56:11 2001 @@ -7,7 +7,7 @@ // // ********************************************** // -// $Id: Upload.php,v 1.14 2001/11/28 17:46:52 cox Exp $ +// $Id: Upload.php,v 1.15 2001/11/28 17:56:11 cox Exp $ /* * Pear File Uploader class. Easy and secure managment of files @@ -18,6 +18,10 @@ * * Leyend: * - you can add error msgs in your language in the HTTP_Upload_Error class +* +* TODO: +* - addapt the class to new upload features of the 4.1 release +* (the new error entry in HTTP_POST_FILES) */ require_once 'PEAR.php'; @@ -279,7 +283,21 @@ */ var $mode_name_selected = false; + /** + * It's a common security risk in pages who has the upload dir + * under the document root (remember the hack of the Apache web?) + * + * @var array + * @access private + * @see HTTP_Upload_File::setValidExtensions() + */ var $_extensions_check = array('php', 'phtm', 'phtml', 'php3', 'inc'); + + /** + * @see HTTP_Upload_File::setValidExtensions() + * @var string + * @access private + */ var $_extensions_mode = 'deny'; /**

« previous php.pear.cvs (#1426) next »