cvs: pear /HTTP_Upload Upload.php
| From: | Thomas V.V.Cox | Date: | Wed, 28 Nov 2001 17:56:11 +0000 |
| Subject: | cvs: pear /HTTP_Upload Upload.php | ||
| Groups: | php.pear.cvs | ||
| Request: | Send a blank email to pear-cvs+get-1426@lists.php.net to get a copy of this message | ||
cox Wed Nov 28 12:56:11 2001 EDT
Modified files:
/pear/HTTP_Upload Upload.php
Log:
more phpdoc comments/TODO
Index: pear/HTTP_Upload/Upload.php
diff -u pear/HTTP_Upload/Upload.php:1.14 pear/HTTP_Upload/Upload.php:1.15
--- pear/HTTP_Upload/Upload.php:1.14 Wed Nov 28 12:46:52 2001
+++ pear/HTTP_Upload/Upload.php Wed Nov 28 12:56:11 2001
@@ -7,7 +7,7 @@
//
// **********************************************
//
-// $Id: Upload.php,v 1.14 2001/11/28 17:46:52 cox Exp $
+// $Id: Upload.php,v 1.15 2001/11/28 17:56:11 cox Exp $
/*
* Pear File Uploader class. Easy and secure managment of files
@@ -18,6 +18,10 @@
*
* Leyend:
* - you can add error msgs in your language in the HTTP_Upload_Error class
+*
+* TODO:
+* - addapt the class to new upload features of the 4.1 release
+* (the new error entry in HTTP_POST_FILES)
*/
require_once 'PEAR.php';
@@ -279,7 +283,21 @@
*/
var $mode_name_selected = false;
+ /**
+ * It's a common security risk in pages who has the upload dir
+ * under the document root (remember the hack of the Apache web?)
+ *
+ * @var array
+ * @access private
+ * @see HTTP_Upload_File::setValidExtensions()
+ */
var $_extensions_check = array('php', 'phtm', 'phtml',
'php3', 'inc');
+
+ /**
+ * @see HTTP_Upload_File::setValidExtensions()
+ * @var string
+ * @access private
+ */
var $_extensions_mode = 'deny';
/**