Req #30849 [Fbk->NoF]: example conf of README.FastCGI is not secure (or: fastcgi + force_redirect)

From: Date: Sun, 29 Jan 2017 04:22:41 +0000
Subject: Req #30849 [Fbk->NoF]: example conf of README.FastCGI is not secure (or: fastcgi + force_redirect)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207011@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=30849&edit=1 ID: 30849 Updated by: php-bugs@lists.php.net Reported by: xuefer at 21cn dot com Summary: example conf of README.FastCGI is not secure (or: fastcgi + force_redirect) -Status: Feedback +Status: No Feedback Type: Feature/Change Request Package: *General Issues Operating System: win PHP Version: 4.3.9 Private report: N New Comment: No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. Previous Comments: ------------------------------------------------------------------------ [2017-01-20 20:27:39] heiglandreas@php.net Is this still relevant? ------------------------------------------------------------------------ [2004-12-29 12:16:45] grange at club-internet dot fr I added a note on http://www.php.net/manual/en/security.cgi-bin.php to achieve the same results with mod_rewrite. ------------------------------------------------------------------------ [2004-12-13 10:10:04] xuefer at 21cn dot com the bug is, "force_redirect" is not implemented by fastcgi sapi, maybe this is a feature request? this lead to same issue as CGI, because both of them use ScriptAlias afaik, ScriptAlias is good for normal cgi program, but bad for scripting-language without "force_redirect" using ScriptAlias http://your-server/fcgi/php-fcgi/abc.php have same issue as: http://your-server/cgi-bin/php-cgi/abc.php the only thing i can do is to use "auto_prepend_file" add a script that check $_SERVER, for REDIRECT_STATUS. this should be better done in api imho. i don't know how to explain, but it's same as cgi. just "force_redirect" don't work and i need it ------------------------------------------------------------------------ [2004-11-20 14:22:23] xuefer at 21cn dot com Description: ------------ sapi/cgi/README.FastCGI (with apache mod_fastcgi) both ScriptAlias(dynserver) or Alias(static server) method issue a security problem. force_redirect is not done for fastcgi, only for cgi this have same problem as cgi with no force_redirect i guess redirect checking can be done after $_SERVER is ready, while cgi use getenv. separate php is not affected by this problem. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=30849&edit=1

« previous php.bugs (#207011) next »