You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP open_basedir被路径拼接绕过问题及解决方案咨询

Why does include __DIR__ . '../parent/my_file.php' bypass open_basedir restrictions?

I'm trying to restrict PHP's file access to a specific directory using open_basedir with this code:

ini_set('open_basedir', __DIR__ . '/my_directory');

Here's what I've noticed:

  • When I use include "../parent/my_file.php", it correctly blocks access to the parent directory file, which matches my expected behavior.
  • But when I use include __DIR__ . '../parent/my_file.php', it bypasses the open_basedir restriction entirely and successfully accesses the parent directory file.

When I check the path of the included file, it shows up as /my_directory/../parent/my_file.php. My guess is that PHP isn't resolving the ../ segment in this path—instead, it's treating it as just a regular part of the path string, so the open_basedir check doesn't recognize it as a reference to the parent directory.

Is my guess correct? And more importantly, is there a way to strictly enforce the open_basedir restriction so that access to parent directories is completely blocked, no matter how the path is constructed?

As a Stack Overflow newbie, I've tried to lay out this issue clearly—thanks in advance for any help!

内容的提问来源于stack exchange,提问作者Develogg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 06:57:19