UntrustedInclusion
error off by defaultGroup: Security · PhpStorm name: UntrustedInclusionInspection
Including a file by a relative path makes PHP search include_path (and the current working directory), so a different file than intended can be loaded. Anchor paths with __DIR__ (or rely on autoloading).
Example
php
<?php
require_once 'lib/boot.php';
include ("views/header.phtml");
$cfg = require('settings.php');
function plugin()
{
$entry = 'plugins/main.php';
include_once $entry;
}
require __DIR__ . '/lib/boot.php';
include '/srv/app/shared.php';
require 'D:/apps/shared.php';
include $dynamic;
include '';
include 'phar://app.phar/boot.php';
include '\\\\fileserver\\shared\\boot.php';Reported:
- line 2: Relative include depends on include_path; anchor it with __DIR__.
- line 3: Relative include depends on include_path; anchor it with __DIR__.
- line 4: Relative include depends on include_path; anchor it with __DIR__.
- line 9: Relative include depends on include_path; anchor it with __DIR__.
Configure
In custos.json:
json
{
"rules": {
"UntrustedInclusion": {
"enabled": true
}
}
}Suppress
Before the statement or declaration (or the first statement of the file), either of:
php
// @custos-ignore UntrustedInclusion
/**
* @noinspection UntrustedInclusionInspection
*/