Bug #14370 Updated: PHP_AUTH_PW being improperly set

From: Date: Thu, 13 Jun 2002 22:14:08 +0000
Subject: Bug #14370 Updated: PHP_AUTH_PW being improperly set
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-10407@lists.php.net to get a copy of this message
ID: 14370 Updated by: sniper@php.net Reported By: henrich@msu.edu -Status: Open +Status: Closed Bug Type: Apache related Operating System: FreeBSD PHP Version: 4.0.6 New Comment: This bug has been fixed in CVS. You can grab a snapshot of the CVS version at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2002-03-11 07:37:49] php4@Ncc-1701.b.shuttle.DE The following patch solves this bug by not exporting the PHP_AUTH_* variables if safe_mode is set. ===8<==================================================== --- php-4.1.2/main/main.c.orig-securevars Mon Dec 17 22:19:51 2001 +++ php-4.1.2/main/main.c Mon Mar 11 07:34:40 2002 @@ -1031,10 +1031,10 @@ } /* PHP Authentication support */ - if (SG(request_info).auth_user) { + if (!PG(safe_mode) && SG(request_info).auth_user) { php_register_variable("PHP_AUTH_USER", SG(request_info).auth_user, array_ptr TSRMLS_CC); } - if (SG(request_info).auth_password) { + if (!PG(safe_mode) && SG(request_info).auth_password) { php_register_variable("PHP_AUTH_PW", SG(request_info).auth_password, array_ptr TSRMLS_CC); } } ------------------------------------------------------------------------ [2002-03-11 07:36:53] php4@Ncc-1701.b.shuttle.DE The following patch solves this bug by not exporting the PHP_AUTH_* variables when safe_mode is set. ===8<==================================================== --- php-4.1.2/main/main.c.orig-securevars Mon Dec 17 22:19:51 2001 +++ php-4.1.2/main/main.c Mon Mar 11 07:34:40 2002 @@ -1031,10 +1031,10 @@ } /* PHP Authentication support */ - if (SG(request_info).auth_user) { + if (!PG(safe_mode) && SG(request_info).auth_user) { php_register_variable("PHP_AUTH_USER", SG(request_info).auth_user, array_ptr TSRMLS_CC); } - if (SG(request_info).auth_password) { + if (!PG(safe_mode) && SG(request_info).auth_password) { php_register_variable("PHP_AUTH_PW", SG(request_info).auth_password, array_ptr TSRMLS_CC); } } ------------------------------------------------------------------------ [2001-12-06 19:34:29] henrich@msu.edu PHP_AUTH_PW is being improperly set when external authentication is active on Apache. I have a directory structure that is protected via Apache authentication, according to the PHP documentation the PHP_AUTH_PW should not be available when external authentication is in use. This is necessary for security concerns when you cannot trust the php applications. In any case, w/ php the AUTH_PW is being set at all times. Please fix, thanks! ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=14370&edit=1

« previous php.bugs (#10407) next »