Sounds almost the best for me ; just check there is no '../a.php' as the last part ; as it could lead to security failure (if the developper didn't do it himself) : 'HelloBundle:Hello:../../config.yml.php' And config.yml is printed without check (don't know the directory structure of Symfony2 ; I will look at it when it will have less changes per month)
So, I believe it's the best proposal in this thread :) Le 27/09/2010 11:23, Tim Nagel a écrit : > Sounds good. > > On Sat, Sep 25, 2010 at 15:43, Fabien Potencier > <fabien.potenc...@symfony-project.com > <mailto:fabien.potenc...@symfony-project.com>> wrote: > > > We can probably find a better naming convention. What about this: > > HelloBundle:Hello:index.php > HelloBundle:Hello:index.twig > > HelloBundle:Hello:index.xml.php > HelloBundle:Hello:index.xml.twig > > That way, when you are using the filesystem loader (and this is the case > 99% of the time), the last part is just the file name. > > What do you think? > > Fabien > > -- > If you want to report a vulnerability issue on symfony, please send it to > security at symfony-project.com > > You received this message because you are subscribed to the Google > Groups "symfony developers" group. > To post to this group, send email to symfony-devs@googlegroups.com > To unsubscribe from this group, send email to > symfony-devs+unsubscr...@googlegroups.com > For more options, visit this group at > http://groups.google.com/group/symfony-devs?hl=en
signature.asc
Description: OpenPGP digital signature