Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:16935 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 83956 invoked by uid 1010); 27 Jun 2005 14:31:26 -0000 Delivered-To: ezmlm-scan-internals@lists.php.net Delivered-To: ezmlm-internals@lists.php.net Received: (qmail 83941 invoked from network); 27 Jun 2005 14:31:26 -0000 Received: from unknown (HELO pb1.pair.com) (127.0.0.1) by localhost with SMTP; 27 Jun 2005 14:31:26 -0000 X-Host-Fingerprint: 82.94.239.5 jdi.jdi-ict.nl Linux 2.5 (sometimes 2.4) (4) Received: from ([82.94.239.5:41747] helo=jdi.jdi-ict.nl) by pb1.pair.com (ecelerity 1.2 r(5656M)) with SMTP id 2A/A5-00424-8BD00C24 for ; Mon, 27 Jun 2005 10:31:21 -0400 Received: from localhost (localhost [127.0.0.1]) by jdi.jdi-ict.nl (8.12.11/8.12.11) with ESMTP id j5REVGlN019631 for ; Mon, 27 Jun 2005 16:31:16 +0200 Received: from localhost (localhost [127.0.0.1]) by jdi.jdi-ict.nl (8.12.11/8.12.11) with ESMTP id j5REVAnB019585; Mon, 27 Jun 2005 16:31:10 +0200 Date: Mon, 27 Jun 2005 16:31:10 +0200 (CEST) X-X-Sender: derick@localhost To: Ilia Alshanetsky cc: Yasuo Ohgaki , Stefan Esser , messju mohr , Matthew Charles Kavanagh , internals@lists.php.net In-Reply-To: <42C00C35.9050500@prohost.org> Message-ID: References: <42BDDC82.6020208@ohgaki.net> <01.6A.54439.491DEB24@pb1.pair.com> <20050626164101.GA11586@dune> <42BEE432.6090307@teh.ath.cx> <20050626175638.GB11586@dune> <42BEEED1.6010602@php.net> <42BF9A46.4060108@ohgaki.net> <42C00C35.9050500@prohost.org> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-Virus-Scanned: by amavisd-new at jci-ict.nl Subject: Re: [PHP-DEV] Re: allow_url_fopen should be INI_ALL From: derick@php.net (Derick Rethans) On Mon, 27 Jun 2005, Ilia Alshanetsky wrote: > IMO disable allow_url_fopen by default is a bad idea as it would break > multitudes of applications that rely on being open URLs via various PHP > functions like getimagesize(), simplexml_load_file(), etc... > > I think Stefan's idea of allowing the setting to be disabled by the script, > but not enabled by it is the best. This way script writers who know which > parts of the app/library do not need the functionality can explicitly disable > it there. +1 here. Derick -- Derick Rethans http://derickrethans.nl | http://ez.no | http://xdebug.org