It was not about a better implentation, such changes are not possible in 5.3.
The goal is to avoid many code duplication and makes sure than any new code has this check in place. I can't think of any other similar patches not present in trunk. On 7 Mar 2011 08:04, "Stas Malyshev" <smalys...@sugarcrm.com> wrote: Hi! > Yes, there was a discussion in progress about adding or not a input > parameter for filenames to... If there are questions about better implementation etc., we have to just check in the 5.3 fix and we can refactor it later. I think it's not good that we allow trunk to have security-related patch not synchronized with 5.3 for months. I wonder if we have more like this. -- Stanislav Malyshev, Software Architect SugarCRM: http://www.sugarcrm.com/ (408)454-6900 ext. 227