Re: PEPr Automated Verification Process - first enhancements
| From: | Justin Patrin | Date: | Sun, 19 Jun 2005 23:00:09 +0000 |
| Subject: | Re: PEPr Automated Verification Process - first enhancements | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-38175@lists.php.net to get a copy of this message | ||
On 6/19/05, Stefano F. Rausch <pear@sf.rausch-e.net> wrote:
> On Sun, 19 Jun 2005 04:01:55 +0200, Alan Knowles <alan@akbkhome.com> wrote:
>
> > On Sat, 2005-06-18 at 18:14 +0200, Stefano F. Rausch wrote:
> >> Dear PEAR-Devs,
> >>
> >> Tobias and I would like to inform you that some of the enhancements regarding the PEPr
> >> process have been committed to cvs.
> >>
> >> What follows is a detailed description of the changes:
> >> +
> >> + case 'pkg_source':
> >> + return
> >> preg_match('"^http\://.+\.(phps|htm(l)?)$"', $url)? true: false;
> > or .txt I guess... - if you dont run .phps on your server, uploading a
> > php file as a .txt, at least get's it rendered...
> >
> > it also rules out people doing stuff like
> >
> > 'http://myapplication/render?name=somefile/xyz.php'
>
> Point taken! Are there any other extensions to be considered too?
>
> Otherwise I would suggest to freeze the possible file types to:
>
> preg_match('"^http\://.+\.(php(s)?|htm(l)?|txt)$", $url)? true: false;
>
> There's still the documentation type that can be used - without any restrictions.
>
A simple preg isn't likely to work very well here. Consider the above
with a slight twist:
'http://myapplication/render?name=somefile/xyz.php&highlight=1'
'http://myapplication/render?name=somefile/xyz.php&highlight=0'
The best thing here to would be to run the URL through Net_URL, check
the protocol to make sure it's http(s) and (possibly) check the
filename to see if it's right. However, consider also:
'http://myapplication/viewFile.asp'
or
'http://myapplication/viewFile.asp?file=somefile.php'
or
'http://myapplication/viewFile.asp?file=1'
While PEAR *is* about PHP it's quite possible that someone could be
using a system for their file upload / viewing in another language.
It's also completely possible to not use extensions, as the "render"
URLs do above. IMHO trying to check file extensions is a limitation we
don't need. It only adds an arbitrary check to the URL. The "type"
select should be enough. If the user lies with the type select the
PEAR Group (or QA, whichever is the right one) can either un-propose
the proposal or remove it.
--
Justin Patrin