PHP open_basedir被路径拼接绕过问题及解决方案咨询
include __DIR__ . '../parent/my_file.php' bypass open_basedir restrictions? I'm trying to restrict PHP's file access to a specific directory using open_basedir with this code:
ini_set('open_basedir', __DIR__ . '/my_directory');
Here's what I've noticed:
- When I use
include "../parent/my_file.php", it correctly blocks access to the parent directory file, which matches my expected behavior. - But when I use
include __DIR__ . '../parent/my_file.php', it bypasses theopen_basedirrestriction entirely and successfully accesses the parent directory file.
When I check the path of the included file, it shows up as /my_directory/../parent/my_file.php. My guess is that PHP isn't resolving the ../ segment in this path—instead, it's treating it as just a regular part of the path string, so the open_basedir check doesn't recognize it as a reference to the parent directory.
Is my guess correct? And more importantly, is there a way to strictly enforce the open_basedir restriction so that access to parent directories is completely blocked, no matter how the path is constructed?
As a Stack Overflow newbie, I've tried to lay out this issue clearly—thanks in advance for any help!
内容的提问来源于stack exchange,提问作者Develogg

