php / php/php-src

allow_url_include warning must be consistent even with path with filters

未关闭
#10,460 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

Bug Status: Needs Triage
主要语言
C
星标
40.4k
派生
8.2k
平均合并
2 天 13 小时
30 天内合并 PR
96

描述

Description

I found this while looking into https://github.com/php/php-src/issues/10453

The following code:

https://3v4l.org/hiiSr

Resulted in this output:

in the include with the same path but with filter, the warning does not mention allow_url_include=0

But I expected this output instead:

2x Warning: include(): data:// wrapper is disabled in the server configuration by allow_url_include=0 ... warning

PHP Version

any

Operating System

any

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从链接的 3v4l 复现程序开始,使用相同的 data:// 路径分别在有过滤器和没有过滤器的情况下比较 include()。跟踪处理 allow_url_include=0 的 PHP include 警告路径,然后验证两条警告都包含预期的设置文本;issue 未指定源文件或测试。

由索引模型根据 Issue 内容生成。

评估

技术栈
c, php
领域
backend, security
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。