Re: AW: AW: AW: [PEAR-DEV] XML_Parser/XML_Tree bugs/problems, post them here please
| From: | Tomas V.V.Cox | Date: | Wed, 10 Sep 2003 12:16:27 +0000 |
| Subject: | Re: AW: AW: AW: [PEAR-DEV] XML_Parser/XML_Tree bugs/problems, post them here please | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-21349@lists.php.net to get a copy of this message | ||
On Wednesday, September 10, 2003 12:47, Marshall Roch wrote:
> Stephan Schmidt wrote:
>>>Umm, let's add a new setInputString() method (there is already a
>>>setInputFile()), ok? So you'll have all the options avaible and we
>>>won't break BC.
>>
>> That's ok for me, but I think it would be OK if setInput would accept a
>> string which will always be treated like an XML string. It's easy to decide
>> whether a resource or string was given but hard to decide whether is a
>> string or a filename...
> The reason for my change was to keep developers from having to guess in
> their own packages, in which case they could miss something (like I did
> with the original regex) that would cause problems. I can't come up
> with *any* examples where a string might get mistaken for a URL, even if
> the string is a cached PHP error or something.
Stephan is right, plus I'd add it opens a posible security issue. For
example if you're using setInput() expecting strings and a guy passes
a valid file name or a url. I even always disable url_fopen_wrappers in my
production servers, as I consider them dangerous in general. Would be nice if I could only
disable only network wrappers not all.
But if people want to be lazy they have the chance with setInput(),
if not, use the strict way choosing setInputFile() or setInputString()
(the new added method).
--
Tomas V.V.Cox mailto:cox@idecnet.com