Req #30849 [Opn->Fbk]: example conf of README.FastCGI is not secure (or: fastcgi + force_redirect)

From: Date: Fri, 20 Jan 2017 20:27:43 +0000
Subject: Req #30849 [Opn->Fbk]: example conf of README.FastCGI is not secure (or: fastcgi + force_redirect)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206786@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=30849&edit=1

 ID:                 30849
 Updated by:         heiglandreas@php.net
 Reported by:        xuefer at 21cn dot com
 Summary:            example conf of README.FastCGI is not secure (or:
                     fastcgi + force_redirect)
-Status:             Open
+Status:             Feedback
 Type:               Feature/Change Request
-Package:            Feature/Change Request
+Package:            *General Issues
 Operating System:   win
 PHP Version:        4.3.9
 Block user comment: N
 Private report:     N

 New Comment:

Is this still relevant?


Previous Comments:
------------------------------------------------------------------------
[2004-12-29 12:16:45] grange at club-internet dot fr

I added a note on http://www.php.net/manual/en/security.cgi-bin.php
to achieve the same results with mod_rewrite.

------------------------------------------------------------------------
[2004-12-13 10:10:04] xuefer at 21cn dot com

the bug is, "force_redirect" is not implemented by fastcgi sapi, maybe this is a feature
request?
this lead to same issue as CGI, because both of them use ScriptAlias
afaik, ScriptAlias is good for normal cgi program, but bad for scripting-language without
"force_redirect"

using ScriptAlias
http://your-server/fcgi/php-fcgi/abc.php
have same issue as:
http://your-server/cgi-bin/php-cgi/abc.php


the only thing i can do is to use "auto_prepend_file" add a script that check $_SERVER,
for REDIRECT_STATUS. this should be better done in api imho.

i don't know how to explain, but it's same as cgi. just "force_redirect"
don't work and i need it

------------------------------------------------------------------------
[2004-11-20 14:22:23] xuefer at 21cn dot com

Description:
------------
sapi/cgi/README.FastCGI (with apache mod_fastcgi)
both ScriptAlias(dynserver) or Alias(static server) method issue a security problem.
force_redirect is not done for fastcgi, only for cgi
this have same problem as cgi with no force_redirect
i guess redirect checking can be done after $_SERVER is ready, while cgi use getenv.

separate php is not affected by this problem.




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=30849&edit=1


Thread (6 messages)

« previous php.bugs (#206786) next »