有没有办法安全地消毒路径输入,而不使用realpath()?
realpath()
目标是防止恶意输入 ../../../../../path/to/file
../../../../../path/to/file
$handle = fopen($path . '/' . $filename, 'r');
php security sanitization
php ×1
sanitization ×1
security ×1