Skip to content

Conversation

@clue
Copy link
Member

@clue clue commented Nov 30, 2017

This PR implements support for max_input_vars and max_input_nesting_level ini settings. These are already supported internally by parse_str(), so this PR adds according functionality for the multipart parser. These settings can only be controlled through ini settings and offering a way to control these here makes little sense. The main use case for these variables is to prevent DOS attacks due to excessive data structures.

This resolves the first part of #257.

@clue clue added this to the v0.8.0 milestone Nov 30, 2017
Copy link
Member

@WyriHaximus WyriHaximus left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@jsor jsor merged commit c09912f into reactphp:master Nov 30, 2017
@clue clue deleted the max-input branch November 30, 2017 13:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants