Does this have any impact on allow_url_include or has that setting
been retained?

Yes, folk do indeed try to do this, for example hitting up Google:
http://www.quora.com/Why-do-include-and-require_once-not-work-with-remote-files

Paddy

On 21 February 2015 at 01:06, Yasuo Ohgaki <yohg...@ohgaki.net> wrote:
> Hi all,
>
> I think this will be the final discussion before vote.
> This RFC is to make PHP stronger against script inclusion attacks just like
> other languages.
>
> https://wiki.php.net/rfc/script_only_include
>
> I hope everyone will like this proposal.
> Thank you all who have participated to discussions.
>
> Those who are not involved, this is the time to check this RFC.
>
> Thank you.
>
> --
> Yasuo Ohgaki
> yohg...@ohgaki.net



-- 

--
Pádraic Brady

http://blog.astrumfutura.com
http://www.survivethedeepend.com
Zend Framework Community Review Team
Zend Framework PHP-FIG Representative

--
PHP Internals - PHP Runtime Development Mailing List
To unsubscribe, visit: http://www.php.net/unsub.php

Reply via email to