allow_url_include warning must be consistent even with path with filters
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 40.4k
- Forks
- 8.1k
- Avg merge
- 2d 13h
- Merged PRs (30d)
- 96
Description
Description
I found this while looking into https://github.com/php/php-src/issues/10453
The following code:
Resulted in this output:
in the include with the same path but with filter, the warning does not mention allow_url_include=0
But I expected this output instead:
2x Warning: include(): data:// wrapper is disabled in the server configuration by allow_url_include=0 ... warning
PHP Version
any
Operating System
any
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the linked 3v4l reproducer and compare include() using the same data:// path with and without the filter. Trace the PHP include warning path that handles allow_url_include=0, then verify that both warnings contain the expected setting text; the issue names no source file or test.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, php
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100