[pLog-general] how to protect your site?

Jon Daley plogworld at daley.snurgle.org
Thu Feb 24 15:21:08 GMT 2005


On Thu, 24 Feb 2005, Oscar Renalias wrote:
> I was looking at enabling Smarty::security
> (http://smarty.php.net/manual/en/variable.security.php) but I found
> that when enabled:
>
> "
> templates can only be included from directories listed in the $secure_dir array.
>
> local files can only be fetched from directories listed in the
> $secure_dir array using {fetch}.

 	I'll bet that templates can be included from the "template 
directory" as well as directories in $secure_dir, so that is why it still 
works.  In the code, there was a comment regaring the "template directory" 
being treated specially.



**************************************************************
*     Jonathan M. Daley     *    Hard work pays off in the   *
*   jondaley at snurgle.org    * future. Laziness pays off now. *
* www.snurgle.org/~jondaley *                                *
**************************************************************



More information about the pLog-general mailing list