Req #30849 [Fbk->NoF]: example conf of README.FastCGI is not secure (or: fastcgi + force_redirect)
| From: | php-bugs at lists dot php dot net | Date: | Sun, 29 Jan 2017 04:22:41 +0000 |
| Subject: | Req #30849 [Fbk->NoF]: example conf of README.FastCGI is not secure (or: fastcgi + force_redirect) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207011@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=30849&edit=1
ID: 30849
Updated by: php-bugs@lists.php.net
Reported by: xuefer at 21cn dot com
Summary: example conf of README.FastCGI is not secure (or:
fastcgi + force_redirect)
-Status: Feedback
+Status: No Feedback
Type: Feature/Change Request
Package: *General Issues
Operating System: win
PHP Version: 4.3.9
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2017-01-20 20:27:39] heiglandreas@php.net
Is this still relevant?
------------------------------------------------------------------------
[2004-12-29 12:16:45] grange at club-internet dot fr
I added a note on http://www.php.net/manual/en/security.cgi-bin.php
to achieve the same results with mod_rewrite.
------------------------------------------------------------------------
[2004-12-13 10:10:04] xuefer at 21cn dot com
the bug is, "force_redirect" is not implemented by fastcgi sapi, maybe this is a feature
request?
this lead to same issue as CGI, because both of them use ScriptAlias
afaik, ScriptAlias is good for normal cgi program, but bad for scripting-language without
"force_redirect"
using ScriptAlias
http://your-server/fcgi/php-fcgi/abc.php
have same issue as:
http://your-server/cgi-bin/php-cgi/abc.php
the only thing i can do is to use "auto_prepend_file" add a script that check $_SERVER,
for REDIRECT_STATUS. this should be better done in api imho.
i don't know how to explain, but it's same as cgi. just "force_redirect"
don't work and i need it
------------------------------------------------------------------------
[2004-11-20 14:22:23] xuefer at 21cn dot com
Description:
------------
sapi/cgi/README.FastCGI (with apache mod_fastcgi)
both ScriptAlias(dynserver) or Alias(static server) method issue a security problem.
force_redirect is not done for fastcgi, only for cgi
this have same problem as cgi with no force_redirect
i guess redirect checking can be done after $_SERVER is ready, while cgi use getenv.
separate php is not affected by this problem.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=30849&edit=1