On Tue, Jan 8, 2013 at 2:38 PM, Nicolai Scheer <nicolai.sch...@gmail.com> wrote:

> I agree, but what about pandora and the other file functions like unlink()
> etc.? :)
> They currently do not prevent such long and prefixed paths...

A bug then, should be fixed. Yes, you don't want to hear that but... :-)

> And to my mind it is ok to let the user open the box (a little?) when he is
> doing so on purpose.
>
> Unfortunately mouting directories is too unflexible for our use case...

How so? can be easily automated for shared hosts and the likes.

> Furthermore we only need to read files, and that's the only function
> currently not allowing the prefix workaround :(


--
Pierre

@pierrejoye | http://blog.thepimp.net | http://www.libgd.org

-- 
PHP Internals - PHP Runtime Development Mailing List
To unsubscribe, visit: http://www.php.net/unsub.php

Reply via email to