Re: security's ALLOW_CONSTANTS

messju mohr <[email protected]>
Newsgroups gmane.comp.php.smarty.devel
Message-ID <[email protected]>
I removed ALLOW_CONSTANTS from $security_settings to avoid further
confusion. We could add and implement it if somebody cares, of course.

On Wed, Feb 25, 2004 at 10:02:56AM -0600, Monte Ohrt wrote:
> ah, I was looking at the wrong thing...
> 
> On Wed, 2004-02-25 at 09:24, messju mohr wrote:
> > On Wed, Feb 25, 2004 at 09:00:46AM -0600, Monte Ohrt wrote:
> > > Hmm, I don't recall that security setting... it was added in version 4.7
> > > of the repository, just 9 commits ago.
> > 
> > Hmm, I find it in all releases down to 2.4.0 . 2.3.1 doesn't have it.
> > But all version only have it defined as false, no version has it
> > implemented.
> > 
> >  
> > > On Tue, 2004-02-24 at 18:18, messju mohr wrote:
> > > > Hello,
> > > > 
> > > > someone on IRC came up with this: There is an element in the
> > > > $security_settings-array "ALLOW_CONSTANTS" (defaulting to false). This
> > > > one is neither documented nor could I find a Smarty version supporting
> > > > this setting.
> > > > 
> > > > I think prohibiting constants in secured templates is useful. AFAIR
> > > > ez_sql relies on the database-connection-parameters (including
> > > > username and password) defined as constants. There may be other libs
> > > > or apps that need constants defined you don't want to expose to an
> > > > untrusted party that is allowd to edit templates.
> > > > 
> > > > Enabling this setting is easy:
> > > > 
> > > > Index: Smarty_Compiler.class.php
> > > > ===================================================================
> > > > RCS file: /repository/smarty/libs/Smarty_Compiler.class.php,v
> > > > retrieving revision 1.315
> > > > diff -u -r1.315 Smarty_Compiler.class.php
> > > > --- Smarty_Compiler.class.php   23 Feb 2004 23:14:40 -0000      1.315
> > > > +++ Smarty_Compiler.class.php   25 Feb 2004 00:08:39 -0000
> > > > @@ -2016,6 +2016,10 @@
> > > >                  break;
> > > > 
> > > >              case 'const':
> > > > +                if ($this->security && !$this->security_settings['ALLOW_CONSTANTS']) {
> > > > +                    $this->_syntax_error("(secure mode) constants not permitted", E_USER_WARNING, __FILE__, __LINE__);
> > > > +                    return;
> > > > +                }
> > > >                  array_shift($indexes);
> > > >                  $_val = $this->_parse_var_props(substr($indexes[0],1));
> > > >                  $compiled_ref = '@constant(' . $_val . ')';
> > > > 
> > > > 
> > > > If there are no objections, I'd like to add this to the Smarty-Compiler.
> > > > 
> > > > 
> > > > greetings
> > > > messju
> > 
> > 
> > !DSPAM:403cbe58246931829411086!
> > 
> > 
> 
> -- 
> Smarty Development Mailing List (http://smarty.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php

-- 
Smarty Development Mailing List (http://smarty.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.