Req #66462 [Com]: Add opcache.api_enabled to provide password-based access to API functions
| From: | krakjoe@php.net | Date: | Sat, 11 Jan 2014 06:29:34 +0000 |
| Subject: | Req #66462 [Com]: Add opcache.api_enabled to provide password-based access to API functions | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-183710@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66462&edit=1
ID: 66462
Comment by: krakjoe@php.net
Reported by: Terry at ellisons dot org dot uk
Summary: Add opcache.api_enabled to provide password-based
access to API functions
Status: Open
Type: Feature/Change Request
Package: opcache
Operating System: N/A
PHP Version: master-Git-2014-01-10 (Git)
Block user comment: N
Private report: N
New Comment:
-1
This is a horrible hack and not required, should you need to secure access to a script utilizing
status functions of opcache then you should do that in the industry standard way, we should not
provide a half baked hack and shout out "we got this" when we haven't, at all ...
Previous Comments:
------------------------------------------------------------------------
[2014-01-10 23:37:31] Terry at ellisons dot org dot uk
Description:
------------
As per README addition:
opcache.api_password (default "")
calling OPcache API functions only from PHP scripts which first
the API by calling opcache_enable_api("password"). This parameter
is set to the MD5 of the required password. Note that if the
opcache.restrict_api is also set then both tests are applied.
The patch is attached
Test script:
---------------
This PHPT validates the functionality:
--TEST--
Validate use of the directive
--INI--
opcache.enable=1
opcache.enable_cli=1
opcache.api_password="e946adb45d4299def2071880d30136d4"
--SKIPIF--
<?php require_once('skipif.inc'); ?>
--FILE--
<?php
var_dump(opcache_get_status());
var_dump(opcache_enable_api("fred"));
var_dump(opcache_get_status());
var_dump(opcache_enable_api("Mary had a little lamb"));
$status = opcache_get_status();
echo "Get status ", (is_array($status) &&
isset($status['scripts'][__FILE__])) ? "works":"fails",
"\n";
?>
--EXPECTF--
Warning: Zend OPcache API is restricted by "api_password" configuration directive in %s on
line 2
bool(false)
Warning: Zend OPcache Invalid API enable password in %s line 3
bool(false)
Warning: Zend OPcache API is restricted by "api_password" configuration directive in %s on
line 4
bool(false)
bool(true)
Get status works
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66462&edit=1