Support Forum

Advanced Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
plugins-topic
allow_url_fopen=0 config causes Uploads Viewer getimagesize fail
Avatar
B. E. Johnson
Member
Free Members
sp_UserOfflineSmall Offline
Sep 9, 2013 - 7:34 am

Do you know of any workaround for this?

Thanks.

Avatar
Yellow Swordfish
Glinton, England
SP Master
sp_UserOfflineSmall Offline
Sep 9, 2013 - 11:35 am

Personally no. Mr papa might have an idea - and he will be along at some time - but I somehow doubt it. If getinagesize() is unable to operate it will return a warning or notice.

The simplistic asnwer, of course, is to turn allow_url_fopen on. Is there a good reason for needing it to be off?

andy-signature.png
YELLOW
SWORDFISH
Avatar
B. E. Johnson
Member
Free Members
sp_UserOfflineSmall Offline
Sep 9, 2013 - 7:10 pm

Yellow Swordfish said
Personally no. Mr papa might have an idea - and he will be along at some time - but I somehow doubt it. If getinagesize() is unable to operate it will return a warning or notice.

The simplistic asnwer, of course, is to turn allow_url_fopen on. Is there a good reason for needing it to be off?

Pretty well known security issues. Our NOC has it off on all of the servers. It can be turned on, on a case-by-case basis, but they discourage it, and not for frivolous reasons. The Show Uploads dialogue still operates, it just has the notices in among the stuff you're looking to interact with. It'll confuse a bunch of people unfamiliar with what it means. If I could figure a way to suppress them only in that location, that would be something of a solution.

 

Avatar
Mr Papa
Simi Valley, CA
SP Master
Free Members
sp_UserOfflineSmall Offline
Sep 9, 2013 - 9:51 pm

I dont there is any reason to use a url wrapper there...  seems like in the plugin sp-uploads-viewer-display.php file, at line 41 (where the getimagesize() is called), we should be able to replace $file with $_POST['dir'] and get the same operation...

give it a try if you want...

I will open a ticket for further research and testing...

Avatar
B. E. Johnson
Member
Free Members
sp_UserOfflineSmall Offline
Sep 10, 2013 - 10:34 pm

Setting that line to:

$imgInfo = getimagesize(htmlentities($_POST['dir'].$file));

works perfectly. Thank You!

Avatar
Mr Papa
Simi Valley, CA
SP Master
Free Members
sp_UserOfflineSmall Offline
Sep 11, 2013 - 1:38 am

thanks...  still need to check for sanitization and security of that change but should cover you until we can update the plugin...

Forum Timezone: Europe/Stockholm
Most Users Ever Online: 1170
Currently Online:
Guest(s) 1
Currently Browsing this Page:
1 Guest(s)
Top Posters:
Mr Papa: 19448
Ike: 2086
Brandon: 864
kvr28: 804
jim: 650
FidoSysop: 577
Conrad_Farlow: 531
fiddlerman: 358
Stefano Prete: 325
Member Stats:
Guest Posters: 619
Members: 17363
Moderators: 0
Admins: 4
Forum Stats:
Groups: 7
Forums: 17
Topics: 10127
Posts: 79625