Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:83382 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 93353 invoked from network); 21 Feb 2015 08:18:51 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 21 Feb 2015 08:18:51 -0000 Authentication-Results: pb1.pair.com smtp.mail=padraic.brady@gmail.com; spf=pass; sender-id=pass Authentication-Results: pb1.pair.com header.from=padraic.brady@gmail.com; sender-id=pass Received-SPF: pass (pb1.pair.com: domain gmail.com designates 209.85.160.175 as permitted sender) X-PHP-List-Original-Sender: padraic.brady@gmail.com X-Host-Fingerprint: 209.85.160.175 mail-yk0-f175.google.com Received: from [209.85.160.175] ([209.85.160.175:55762] helo=mail-yk0-f175.google.com) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id F6/D2-08895-96F38E45 for ; Sat, 21 Feb 2015 03:18:50 -0500 Received: by mail-yk0-f175.google.com with SMTP id q200so9238046ykb.6 for ; Sat, 21 Feb 2015 00:18:46 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding; bh=DL6h219V9EMkH/hYGAVnqSUE9uNLw9pz6GYsD9udXdM=; b=LqS6eMhhIWsU1ufJ0bM5RJvEbx2CL/w0tnry/jTvUw1lnbQody6amXjDYllIR7vqGd Dk4+AiZmd6p0V+ZMpE84awAA7vPWv1srQke29cbm+2GP1A8y0yHT+FENUkKuPJhvBQxP ANwhoF9Hu3oytHtLedXXCSJQch8Jla2PgY9C2dPt5Nye446Hie8ZUZueRY9WS/hd5j2y v2zzi2R9R1ULArGexsvaOeEaKGHAEv0m415/+0eTdysLxcwhTOiOV01p0S4kekxveqH6 f7w4pP0jn/AWgXgyjN6ksrfulaZU7NzMvdY9r5LwS++5dBUS3TrzkkhBAIJoy8KAVqVr M+NA== MIME-Version: 1.0 X-Received: by 10.236.220.168 with SMTP id o38mr1453184yhp.32.1424506726057; Sat, 21 Feb 2015 00:18:46 -0800 (PST) Received: by 10.170.222.86 with HTTP; Sat, 21 Feb 2015 00:18:45 -0800 (PST) In-Reply-To: References: Date: Sat, 21 Feb 2015 08:18:45 +0000 Message-ID: To: Yasuo Ohgaki Cc: "internals@lists.php.net" Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Subject: Re: [PHP-DEV] [RFC] [FINAL DISCUSSION] Script only include/require From: padraic.brady@gmail.com (=?UTF-8?Q?P=C3=A1draic_Brady?=) Does this have any impact on allow_url_include or has that setting been retained? Yes, folk do indeed try to do this, for example hitting up Google: http://www.quora.com/Why-do-include-and-require_once-not-work-with-remote-f= iles Paddy On 21 February 2015 at 01:06, Yasuo Ohgaki wrote: > Hi all, > > I think this will be the final discussion before vote. > This RFC is to make PHP stronger against script inclusion attacks just li= ke > other languages. > > https://wiki.php.net/rfc/script_only_include > > I hope everyone will like this proposal. > Thank you all who have participated to discussions. > > Those who are not involved, this is the time to check this RFC. > > Thank you. > > -- > Yasuo Ohgaki > yohgaki@ohgaki.net --=20 -- P=C3=A1draic Brady http://blog.astrumfutura.com http://www.survivethedeepend.com Zend Framework Community Review Team Zend Framework PHP-FIG Representative