[TYPO3-core] RFC: allow .. in names -> check for ../ (#3364)

Karsten Dambekalns karsten at typo3.org
Wed May 3 16:07:03 CEST 2006


Hi.

On Saturday 29 April 2006 20:22, Martin Kutschker wrote:
> I mean the check currently denies any .. within the path.
>
> So "foo..bar" is invalid without any real reason. What should be forbidden
> is "../foo/bar" or "fo/../bar":
>
> preg_match('|(?:^\.\.|/\.\./|',$path)

Fine with me if that check is used. But just to educate me: what is the ?: 
needed for?

Karsten
-- 
Karsten Dambekalns
TYPO3 Association - Active Member
http://association.typo3.org/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 309 bytes
Desc: not available
Url : http://lists.netfielders.de/pipermail/typo3-team-core/attachments/20060503/68f9f741/attachment.pgp 


More information about the TYPO3-team-core mailing list