Bug #28349 [Com]: display_errors = off is ignored

From: Date: Mon, 14 Nov 2016 11:53:51 +0000
Subject: Bug #28349 [Com]: display_errors = off is ignored
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205355@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=28349&edit=1

 ID:                 28349
 Comment by:         matt at equaliser dot net
 Reported by:        jonathan at nationaldirect dot net
 Summary:            display_errors = off is ignored
 Status:             Not a bug
 Type:               Bug
 Package:            Output Control
 Operating System:   Win2k
 PHP Version:        4.3.6
 Block user comment: N
 Private report:     N

 New Comment:

Just so we're absolutely clear on this: if a production server runs out of disk space or has
permission issue which caused the logfile to be unwriteable, PHP will start displaying server errors
to the end user?

This sounds exceptionally dangerous.


Previous Comments:
------------------------------------------------------------------------
[2004-06-25 11:06:35] tri at tactile3d dot com

Hmmm, kinda disagree about the "bogus" status.  It may be behaving "as designed"
but it's an unclear design.  A tag that says display_errors Off should turn them off!  The tag
isn't called display_errors_if_on_or_(if_off)_when_cannot_write_to_some_other_output.

At the very least, as jonathan suggested, there should be a comment in the php.ini that describes
this behaviour.

--tristan

------------------------------------------------------------------------
[2004-06-08 09:48:11] derick@php.net

You just need to setup your server correctly, this has nothing to do with a "security"
problem. Not a bug in PHP -> bogus.

------------------------------------------------------------------------
[2004-06-07 17:17:48] jonathan at nationaldirect dot net

I still think we need to put a warning somewhere because this is a potential security risk.  Maybe
we could let the user choose what to do by putting a setting in the php.ini file.

------------------------------------------------------------------------
[2004-06-07 17:07:11] jonathan at nationaldirect dot net

On a production machine we cannot display errors to the end user because of the privacy and security
risks.  I think if we put a comment in the php.ini file to warn windows users of this issue and also
quietly discard the errors if the file cannot be written to then it would be more acceptable.

------------------------------------------------------------------------
[2004-06-07 17:03:55] iliaa@php.net

Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php

When you specified a log file that can not be written to, 
it is better to display the error rather then hide it and 
lose the record that is had every occurred. 

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=28349


--
Edit this bug report at https://bugs.php.net/bug.php?id=28349&edit=1


Thread (17 messages)

« previous php.bugs (#205355) next »