Req #74995 [NEW]: Control/set fastcgi parameters from pool config file.
| From: | email at davekok dot nl | Date: | Thu, 27 Jul 2017 09:42:24 +0000 |
| Subject: | Req #74995 [NEW]: Control/set fastcgi parameters from pool config file. | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-210366@lists.php.net to get a copy of this message | ||
From: email at davekok dot nl
Operating system: all
PHP version: Next Minor Version
Package: FPM related
Bug Type: Feature/Change Request
Bug description:Control/set fastcgi parameters from pool config file.
Description:
------------
In the age of microservices, containers and front controllers, it would
be useful to control/set fastcgi parameters not just in the webserver
config but also in the pool config. Webservers will still need to push
the basic stuff like the REQUEST_URI and other parameters. However for a
pool that serves only one microservice which has one front controller,
it would be useful to set the SCRIPT_FILENAME in the pool config. Both
as a security feature, so if the webserver is compromised in anyway the
microservice (assuming it is run else where) can not easily be fooled to
do other stuff by changing the SCRIPT_FILENAME parameter. But also as a
means to decouple webserver configuration as much as possible from the
microservice configuration. The less the webserver needs to known about
the microservices it proxies, the easier it is to config it.
And just in case it becomes a thing, prevent parameter injection by
specifying which parameters fpm is allowed to load from the input. So if
an attacker finds a way around the webserver or through the webserver
the attack surface is as small as possible.
Expected result:
----------------
nginx:
upstream sales-service {
server sales-service1.internal:7000 weight=5;
server sales-service2.internal:7000 weight=5;
server sales-service3.internal:7000 weight=5;
}
server {
listen 443;
server_name customer-portal.example;
location ~ ^/api/sales-service(?<apiUri>/.*) {
include snippets/standard-parameters.conf;
fastcgi_param REQUEST_URI $apiUri;
fastcgi_pass sales-service;
}
}
pool.d/sales-service.conf:
[sales-service]
chdir = /srv/$pool/web
# prevent any other script from being loaded
set fastcgi_param[SCRIPT_FILENAME] = app.php
# only start the script if the required parameters are present
require fastcgi_param[REQUEST_METHOD]
require fastcgi_param[REQUEST_URI]
require fastcgi_param[SERVER_NAME]
require fastcgi_param[SERVER_PORT]
# this will not ensure https off course, but will aid in
# case of misconfiguration
require fastcgi_param[HTTPS]
# allow these parameters any thing is ignored and not exposed to script
allow fastcgi_param[CONTENT_LENGTH]
allow fastcgi_param[CONTENT_TYPE]
allow fastcgi_param[REMOTE_ADDR]
allow fastcgi_param[REMOTE_PORT]
allow fastcgi_param[SERVER_ADDR]
...
Actual result:
--------------
nginx:
upstream sales-service {
server sales-service1.internal:7000 weight=5;
server sales-service2.internal:7000 weight=5;
server sales-service3.internal:7000 weight=5;
}
server {
listen 443;
server_name customer-portal.example;
location ~ ^/api/sales-service(?<apiUri>/.*) {
include snippets/standard-parameters.conf;
fastcgi_param REQUEST_URI $apiUri;
fastcgi_param SCRIPT_FILENAME app.php;
fastcgi_pass sales-service;
}
}
pool.d/sales-service.conf:
[sales-service]
chdir = /srv/$pool/web
...
--
Edit bug report at https://bugs.php.net/bug.php?id=74995&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74995&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74995&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74995&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74995&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74995&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74995&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74995&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74995&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74995&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74995&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74995&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74995&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74995&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74995&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74995&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74995&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74995&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74995&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74995&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74995&r=mysqlcfg