Re: PEPr Automated Verification Process - first enhancements

From: Date: Sun, 19 Jun 2005 23:00:09 +0000
Subject: Re: PEPr Automated Verification Process - first enhancements
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-38175@lists.php.net to get a copy of this message
On 6/19/05, Stefano F. Rausch <pear@sf.rausch-e.net> wrote: > On Sun, 19 Jun 2005 04:01:55 +0200, Alan Knowles <alan@akbkhome.com> wrote: > > > On Sat, 2005-06-18 at 18:14 +0200, Stefano F. Rausch wrote: > >> Dear PEAR-Devs, > >> > >> Tobias and I would like to inform you that some of the enhancements regarding the PEPr > >> process have been committed to cvs. > >> > >> What follows is a detailed description of the changes: > >> + > >> + case 'pkg_source': > >> + return > >> preg_match('"^http\://.+\.(phps|htm(l)?)$"', $url)? true: false; > > or .txt I guess... - if you dont run .phps on your server, uploading a > > php file as a .txt, at least get's it rendered... > > > > it also rules out people doing stuff like > > > > 'http://myapplication/render?name=somefile/xyz.php' > > Point taken! Are there any other extensions to be considered too? > > Otherwise I would suggest to freeze the possible file types to: > > preg_match('"^http\://.+\.(php(s)?|htm(l)?|txt)$", $url)? true: false; > > There's still the documentation type that can be used - without any restrictions. > A simple preg isn't likely to work very well here. Consider the above with a slight twist: 'http://myapplication/render?name=somefile/xyz.php&highlight=1' 'http://myapplication/render?name=somefile/xyz.php&highlight=0' The best thing here to would be to run the URL through Net_URL, check the protocol to make sure it's http(s) and (possibly) check the filename to see if it's right. However, consider also: 'http://myapplication/viewFile.asp' or 'http://myapplication/viewFile.asp?file=somefile.php' or 'http://myapplication/viewFile.asp?file=1' While PEAR *is* about PHP it's quite possible that someone could be using a system for their file upload / viewing in another language. It's also completely possible to not use extensions, as the "render" URLs do above. IMHO trying to check file extensions is a limitation we don't need. It only adds an arbitrary check to the URL. The "type" select should be enough. If the user lies with the type select the PEAR Group (or QA, whichever is the right one) can either un-propose the proposal or remove it. -- Justin Patrin

« previous php.pear.dev (#38175) next »