Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
32 commits
Select commit Hold shift + click to select a range
e3f29b4
Merge pull request #1 from php/master
chopins Sep 2, 2020
f97a395
Merge pull request #2 from php/master
chopins Sep 8, 2020
9850245
Merge pull request #3 from php/master
chopins Sep 12, 2020
728d914
Merge pull request #4 from php/master
chopins Sep 16, 2020
ee2ba03
Merge pull request #5 from php/master
chopins Sep 20, 2020
ee22aa4
Merge pull request #6 from php/master
chopins Oct 1, 2020
86e41ca
Merge pull request #7 from php/master
chopins Oct 3, 2020
dd61db7
Merge pull request #8 from php/master
chopins Nov 12, 2020
725f0ef
Merge pull request #9 from php/master
chopins Dec 17, 2020
2032ee3
Merge pull request #10 from php/master
chopins Nov 16, 2021
7fa87be
Merge pull request #11 from php/master
chopins Nov 21, 2021
d4b78af
Merge pull request #12 from php/master
chopins Dec 6, 2021
e80e7c1
Merge pull request #13 from php/master
chopins Dec 24, 2021
a29017a
Merge pull request #14 from php/master
chopins Dec 26, 2021
adf3789
Merge pull request #15 from php/master
chopins Mar 24, 2022
b510ebd
Merge pull request #16 from php/master
chopins Apr 10, 2022
bda9813
Merge pull request #17 from php/master
chopins May 16, 2022
02d022a
Merge pull request #18 from php/master
chopins May 21, 2022
f8c032e
Merge pull request #19 from php/master
chopins Nov 29, 2022
2c54b72
Merge pull request #20 from php/master
chopins Dec 14, 2022
86402dc
Merge pull request #21 from php/master
chopins May 5, 2023
dbdff8a
Merge pull request #22 from php/master
chopins Jun 15, 2023
c44507a
Merge branch 'php:master' into master
chopins Aug 21, 2023
5f41c1b
Merge pull request #23 from php/master
chopins Mar 1, 2024
265af42
Merge pull request #24 from php/master
chopins Apr 27, 2024
3e84b8e
Merge pull request #25 from php/master
chopins May 20, 2024
8d75d84
Merge branch 'php:master' into master
chopins Jun 19, 2024
45e2f63
Merge pull request #26 from php/master
chopins Apr 7, 2025
32996a4
Merge pull request #27 from php/master
chopins Sep 18, 2025
d6d7bb8
Merge pull request #28 from php/master
chopins Dec 17, 2025
63b1c52
Merge pull request #29 from php/master
chopins Jan 28, 2026
a92fc9f
add multipart_uri_whitelist INI option
chopins Feb 3, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions main/SAPI.h
Original file line number Diff line number Diff line change
Expand Up @@ -141,6 +141,7 @@ typedef struct _sapi_globals_struct {
char *default_charset;
HashTable *rfc1867_uploaded_files;
zend_long post_max_size;
char *multipart_uri_whitelist;
int options;
bool sapi_started;
double global_request_time;
Expand Down
1 change: 1 addition & 0 deletions main/main.c
Original file line number Diff line number Diff line change
Expand Up @@ -878,6 +878,7 @@ PHP_INI_BEGIN()
PHP_INI_ENTRY("disable_functions", "", PHP_INI_SYSTEM, NULL)
PHP_INI_ENTRY("max_file_uploads", "20", PHP_INI_SYSTEM|PHP_INI_PERDIR, NULL)
PHP_INI_ENTRY("max_multipart_body_parts", "-1", PHP_INI_SYSTEM|PHP_INI_PERDIR, NULL)
STD_PHP_INI_ENTRY("multipart_uri_whitelist", NULL, PHP_INI_PERDIR, OnUpdateString, multipart_uri_whitelist, sapi_globals_struct, sapi_globals)

STD_PHP_INI_BOOLEAN("allow_url_fopen", "1", PHP_INI_SYSTEM, OnUpdateBool, allow_url_fopen, php_core_globals, core_globals)
STD_PHP_INI_BOOLEAN("allow_url_include", "0", PHP_INI_SYSTEM, OnUpdateBool, allow_url_include, php_core_globals, core_globals)
Expand Down
19 changes: 19 additions & 0 deletions main/rfc1867.c
Original file line number Diff line number Diff line change
Expand Up @@ -670,6 +670,7 @@ SAPI_API SAPI_POST_HANDLER_FUNC(rfc1867_post_handler)
zend_long post_max_size = REQUEST_PARSE_BODY_OPTION_GET(post_max_size, SG(post_max_size));
zend_long max_input_vars = REQUEST_PARSE_BODY_OPTION_GET(max_input_vars, PG(max_input_vars));
zend_long upload_max_filesize = REQUEST_PARSE_BODY_OPTION_GET(upload_max_filesize, PG(upload_max_filesize));
char *multipart_uri_whitelist = SG(multipart_uri_whitelist);
const zend_encoding *internal_encoding = zend_multibyte_get_internal_encoding();
php_rfc1867_getword_t getword;
php_rfc1867_getword_conf_t getword_conf;
Expand All @@ -694,6 +695,24 @@ SAPI_API SAPI_POST_HANDLER_FUNC(rfc1867_post_handler)
_basename = php_ap_basename;
}

if(multipart_uri_whitelist != NULL) {
char *uri = strtok(multipart_uri_whitelist, ":");
bool find = 0;

while (uri)
{
if(strcasecmp(SG(request_info).request_uri, uri) == 0) {
find = 1;
break;
}
uri = strtok(NULL, ":");
}
if(!find) {
EMIT_WARNING_OR_ERROR("request uri %s is not allow POST multipart body", SG(request_info).request_uri);
return;
}
}

if (post_max_size > 0 && SG(request_info).content_length > post_max_size) {
EMIT_WARNING_OR_ERROR("POST Content-Length of " ZEND_LONG_FMT " bytes exceeds the limit of " ZEND_LONG_FMT " bytes", SG(request_info).content_length, post_max_size);
return;
Expand Down
Loading