cvs: smarty /libs/core core.is_secure.php

"Messju Mohr" <[email protected]>
Newsgroups gmane.comp.php.cvs.smarty
Message-ID <cvsmessju1079638597@cvsserver>
messju		Thu Mar 18 14:36:37 2004 EDT

  Modified files:              
    /smarty/libs/core	core.is_secure.php 
  Log:
  removed merging of $smarty->template_dir into $smarty->secure_dir
  
  the resource_base_path is considerd secure instead. this change should
  have absolutely no impact on smarty's security's behaviour
  
  
  
http://cvs.php.net/diff.php/smarty/libs/core/core.is_secure.php?r1=1.7&r2=1.8&ty=u
Index: smarty/libs/core/core.is_secure.php
diff -u smarty/libs/core/core.is_secure.php:1.7 smarty/libs/core/core.is_secure.php:1.8
--- smarty/libs/core/core.is_secure.php:1.7	Mon Feb 23 19:10:55 2004
+++ smarty/libs/core/core.is_secure.php	Thu Mar 18 14:36:36 2004
@@ -17,41 +17,42 @@
 
 function smarty_core_is_secure($params, &$smarty)
 {
-    static $check_template_dir = true;
-
     if (!$smarty->security || $smarty->security_settings['INCLUDE_ANY']) {
         return true;
     }
 
-    $_smarty_secure = false;
     if ($params['resource_type'] == 'file') {
-        if($check_template_dir) {
-            if (!in_array($smarty->template_dir, $smarty->secure_dir))
-                // add template_dir to secure_dir array
-                array_unshift($smarty->secure_dir, $smarty->template_dir);
-            $check_template_dir = false;
+        $_rp = realpath($params['resource_name']);
+        if (isset($params['resource_base_path'])) {
+            foreach ((array)$params['resource_base_path'] as $curr_dir) {
+                if ( !empty($curr_dir) && is_readable ($curr_dir)) {
+                    $_cd = realpath($curr_dir);
+                    if (strncmp($_rp, $_cd, strlen($_cd)) == 0
+                        && $_rp{strlen($_cd)} == DIRECTORY_SEPARATOR ) {
+                        return true;
+                    }
+                }
+            }
         }
         if (!empty($smarty->secure_dir)) {
-            $_rp = realpath($params['resource_name']);
             foreach ((array)$smarty->secure_dir as $curr_dir) {
                 if ( !empty($curr_dir) && is_readable ($curr_dir)) {
                     $_cd = realpath($curr_dir);
                     if (strncmp($_rp, $_cd, strlen($_cd)) == 0
                         && $_rp{strlen($_cd)} == DIRECTORY_SEPARATOR ) {
-                        $_smarty_secure = true;
-                        break;
+                        return true;
                     }
                 }
             }
         }
     } else {
         // resource is not on local file system
-        $_smarty_secure = call_user_func_array(
+        return call_user_func_array(
             $smarty->_plugins['resource'][$params['resource_type']][0][2],
             array($params['resource_name'], &$smarty));
     }
 
-    return $_smarty_secure;
+    return false;
 }
 
 /* vim: set expandtab: */

-- 
Smarty CVS Mailing List (http://cvs.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.