Req #51595 [Com]: passing ini settings via FASTCGI parameters

From: Date: Fri, 29 Apr 2016 14:56:18 +0000
Subject: Req #51595 [Com]: passing ini settings via FASTCGI parameters
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200833@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=51595&edit=1

 ID:                 51595
 Comment by:         ouroboros_17 at hotmail dot com
 Reported by:        fat@php.net
 Summary:            passing ini settings via FASTCGI parameters
 Status:             Closed
 Type:               Feature/Change Request
 Package:            FPM related
 Operating System:   any
 PHP Version:        trunk
 Assigned To:        fat
 Block user comment: N
 Private report:     N

 New Comment:

Some security warning should be given in the FPM documentation:
if someone can upload a .htaccess in a directory and set environment variable (PHP_ADMIN_VALUE), he
can easily overwrite the PHP pool configuration. I don't know if it was intended, but you must
put "AllowOverride None" in your Apache configuration.
When PHP is a module of Apache it is possible to set php_value in .htaccess, but at least it is
impossible to set php_admin_value. IMHO it's a security flaw in FPM.


Previous Comments:
------------------------------------------------------------------------
[2015-06-19 12:52:13] bart dot tapolsky at gmail dot com

It works fine with nginx:
fastcgi_param PHP_VALUE param1=val1

But how can I set two or more php variables?

fastcgi_param PHP_VALUE param1=val1
fastcgi_param PHP_VALUE param2=val2

does not work because 2nd line replace PHP_VALUE from the 1st line

------------------------------------------------------------------------
[2014-08-14 16:54:19] ethan at piliavin dot com

FYI, I was finally able to get this working on nginx by quoting and escaping the values..

fastcgi_param  PHP_ADMIN_VALUE
"error_log=\"/srv/http/domain.com/logs/php.log\"";

------------------------------------------------------------------------
[2013-10-30 14:01:46] glen at delfi dot ee

actually, no quotes are neccessary, and single quotes work too:

setenv.add-environment += ( "PHP_VALUE" => "
    user_agent=ff2 dd
    user_ini.filename='.php.user.ini'
    memory_limit=501M
"
)

parse as:
param[user_agent]: string(6) "ff2 dd"
param[user_ini.filename]: string(14) ".php.user2.ini"
param[memory_limit]: string(4) "501M"

------------------------------------------------------------------------
[2013-10-30 13:54:55] glen at delfi dot ee

It is possible to pass variables in lighttpd 1.4:


setenv.add-environment += ( "PHP_VALUE" => "
    user_agent=\"ff\"
    user_ini.filename=\".php.user.ini\"
    memory_limit=\"500M\"
"
)

you need to use raw newlines to separate values and of course escape quotes for lighttpd config
parser

------------------------------------------------------------------------
[2013-09-09 02:20:45] moswh07 at gmail dot com

I've been got the same problem, which I get 
$_SERVER["PHP_VALUE"] = '...'
 in php.ini when I use 
fastcgi_param PHP_ADMIN_VALUE ...
in nginx config.

I find the solution that spawn-cgi may not support this feature.
the newest updated of spawn is 1.6.3 which was published in 2009-09-23.
but we can see from this page that the feature was added in 2010-04-19 and only 
supported in php-fpm.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=51595


--
Edit this bug report at https://bugs.php.net/bug.php?id=51595&edit=1


Thread (14 messages)

« previous php.bugs (#200833) next »