Re: [SMARTY-DEV] $smarty.const

[email protected] (Monte Ohrt)
Newsgroups php.smarty.dev
Message-ID <[email protected]>
I have no problems with that patch, you have my vote to implement it.

messju mohr wrote:

>On Thu, Sep 09, 2004 at 03:49:57PM -0700, boots wrote:
>  
>
>>Hi all.
>>
>>It occured to me that even with security on we might be leaking data
>>through $smarty.const (eg: SMARTY_DIR which reveals a system path). I
>>would like to propose that either $smarty.const is made unavailable
>>when security is on (my ideal) or that somehow only white-listed keys
>>can be retrieved through $smarty.const.
>>
>>If this is acceptable, I'd be happy to prepare a patch.
>>
>>It may also be desirable to disable the request vars when security is
>>on, but I won't venture that far for now :)
>>    
>>
>
>just FYI: i suggested something like that quite some time ago:
>http://marc.theaimsgroup.com/?l=smarty-dev&m=107766831414634&w=2
>
>i didn't get any real feedback on that. go ahead, maybe you have more
>luck! :)
>
>  
>
>>xo boots
>>    
>>
>
>  
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.