live627

  • Should five per cent appear too small / Be thankful I don't take it all / 'Cause I'm the taxman, yeah I'm the taxman
  • Messages: 1 670
WebGet and open_basedir
« le 1er Août 2012 à 06:31 »
On the last page of the installer, I see some of these errors:


Warning: curl_setopt() [function.curl-setopt]: CURLOPT_FOLLOWLOCATION cannot be activated when safe_mode is enabled or an open_basedir is set in ./Sources/Class-WebGet.php on line 150
A confident man keeps quiet.whereas a frightened man keeps talking, hiding his fear.

Arantor

  • As powerful as possible, as complex as necessary.
  • Messages: 14 278
Re: WebGet and open_basedir
« Réponse #1, le 1er Août 2012 à 14:51 »
There's actually a fix documented on php.net for this, and I'll implement it when I have time, but I have to say while I can understand the restriction in the stupid 'safe mode', I have no idea why it's restricted with open_basedir.
When we unite against a common enemy that attacks our ethos, it nurtures group solidarity. Trolls are sensational, yes, but we keep everyone honest. | Game Memorial

Norodo

  • Oh you Baidu, so randumb. (60 sites being indexed at once? Jeez)
  • Messages: 469
Re: WebGet and open_basedir
« Réponse #2, le 1er Août 2012 à 15:05 »
Safe mode is so annoying. I had to deal with it all of the time when I had NFSNET as my host. It's pretty much their only drawback for me.

Arantor

  • As powerful as possible, as complex as necessary.
  • Messages: 14 278
Re: WebGet and open_basedir
« Réponse #3, le 1er Août 2012 à 15:11 »
It has been dropped from later PHP releases simply because it doesn't actually add anything useful as far as safety goes.

Nao

  • Dadman with a boy
  • Messages: 16 082
Re: WebGet and open_basedir
« Réponse #4, le 1er Août 2012 à 16:01 »
Well, even after the good ol' days of Safe Mode, remember how we got mod_security for Apache, the infamous module that would crash on you if you dared to enter ";id=" in the URL...? :P

Arantor

  • As powerful as possible, as complex as necessary.
  • Messages: 14 278
Re: WebGet and open_basedir
« Réponse #5, le 1er Août 2012 à 16:03 »
There are way more rules in mod_security than that. Some of the configurations are downright weird, too.

(Yes, the host can actually configure what shows up in mod_security. I remember one host who used to actually kick back *any* requested URL with ; in it. Guess how that worked out for him.)

Dragooon

  • I can code! Really!
  • polygon.com has to be one of the best sites I've seen recently.
  • Messages: 1 841
Re: WebGet and open_basedir
« Réponse #6, le 1er Août 2012 à 18:41 »
Citation de Nao le 1er Août 2012 à 16:01
Well, even after the good ol' days of Safe Mode, remember how we got mod_security for Apache, the infamous module that would crash on you if you dared to enter ";id=" in the URL...? :P
That's why you changed AeMe to use ;in= :o, never knew that.
The way it's meant to be

Arantor

  • As powerful as possible, as complex as necessary.
  • Messages: 14 278

Nao

  • Dadman with a boy
  • Messages: 16 082
Re: WebGet and open_basedir
« Réponse #8, le 1er Août 2012 à 19:38 »
Citation de Dragooon le 1er Août 2012 à 18:41
That's why you changed AeMe to use ;in= :o, never knew that.
Yup, was tired of the fake "bug reports"...
SMF did it by changing 'id' to 'tid' or whatever was the first letter of their variable (topic, message...), I decided to adopt a single name that would stand for 'id number' and just replace 'id'... Happy with it.

Arantor

  • As powerful as possible, as complex as necessary.
  • Messages: 14 278
Re: WebGet and open_basedir
« Réponse #9, le 20 Février 2013 à 02:51 »
Bumping to remind myself to fix this. I do now know and understand why it is in place, I just haven't implemented it yet.