Req #41620 [Com]: Can't pass VirtualDocumentRoot Vars

From: Date: Sun, 11 Dec 2016 21:22:14 +0000
Subject: Req #41620 [Com]: Can't pass VirtualDocumentRoot Vars
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205919@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=41620&edit=1

 ID:                 41620
 Comment by:         dustyscholtz at gmx dot net
 Reported by:        ruud at rb-sound dot nl
 Summary:            Can't pass VirtualDocumentRoot Vars
 Status:             Not a bug
 Type:               Feature/Change Request
 Package:            Feature/Change Request
 Operating System:   FreeBSD
 PHP Version:        5.2.3
 Block user comment: N
 Private report:     N

 New Comment:

10 years later and still no solution?


Previous Comments:
------------------------------------------------------------------------
[2007-06-07 08:23:08] tony2001@php.net

The %0 thing is supported by mod_vhost_alias.
We do not plan to re-implement it in PHP, but we would gladly review a patch.

------------------------------------------------------------------------
[2007-06-07 08:03:13] ruud at rb-sound dot nl

%0 is the full name of the virtual host.
For masshosting you can use this type of variables to create a dynamic configuration.

If you use a config like this :
VirtualDocumentRoot /usr/www_data/%0/www/public_html/

And you vist www.example.tld
Apache will start serving from /usr/www_data/www.example.tld/www/public_html/

If you visit www.test.tld
Apache will start serving from /usr/www_data/www.test.tld/www/public_html/

For security reasons you want to chroot php to one level up.
For example 1 you want the following setting
php_admin_value open_basedir /usr/www_data/www.example.tld/www/
With this setting php can't reach the files of www.test.tld if your visiting www.example.tld.
But can reach files one level up.

Php doesn't process the vars of apache.

For a full description of other var command please check.
http://httpd.apache.org/docs/2.2/mod/mod_vhost_alias.html\

If this function works you can secure every domain and still run php as the www user for every
domain.

------------------------------------------------------------------------
[2007-06-07 07:50:31] tony2001@php.net

>The %0 only works on VirtualDocumentRoot. 
>php doens't read the %0 value.

What %0 is supposed to mean?


------------------------------------------------------------------------
[2007-06-07 07:40:13] ruud at rb-sound dot nl

Apache reports bug as a php bug
http://issues.apache.org/bugzilla/show_bug.cgi?id=42606

------------------------------------------------------------------------
[2007-06-07 07:38:58] ruud at rb-sound dot nl

Description:
------------
php_admin_value open_basedir /usr/local/apache/vhosts/%0/www/

The %0 only works on VirtualDocumentRoot. php doens't read the %0 value.

Reproduce code:
---------------
In this example i try to chroot php. So user's can only access there home dir.

<VirtualHost *> 
Use CanonicalName off  # use the name from the Host: header instead of the DNS name
VirtualDocumentRoot /usr/local/apache/vhosts/%0/www/public_html/
php_admin_value open_basedir /usr/local/apache/vhosts/%0/www/
<VirtualHost>

The %0 only works on VirtualDocumentRoot. php doens't read the %0 value.

Expected result:
----------------
php_admin_value open_basedir /usr/local/apache/vhosts/www.domain.tld/www/



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=41620&edit=1


Thread (6 messages)

« previous php.bugs (#205919) next »