Req #14071 [Opn->Csd]: 'admin-values' php.ini also for CGI-binary

From: Date: Mon, 23 Oct 2017 00:25:53 +0000
Subject: Req #14071 [Opn->Csd]: 'admin-values' php.ini also for CGI-binary
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211835@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=14071&edit=1

 ID:                 14071
 Updated by:         kalle@php.net
 Reported by:        maddog2k at maddog2k dot nl
 Summary:            'admin-values' php.ini also for CGI-binary
-Status:             Open
+Status:             Closed
 Type:               Feature/Change Request
 Package:            PHP options/info functions
 Operating System:   Linux/FreeBSD
 PHP Version:        4.0.6
-Assigned To:        
+Assigned To:        kalle
 Block user comment: N
 Private report:     N

 New Comment:

I'm not sure at what point the php-cgi -c option was introduced, but it seems more reasonable
to simply supply the CGI SAPI of PHP with a specific php.ini file using php-cgi -c /path/to/php.ini

Please re-open if this still is an issue with PHP7


Previous Comments:
------------------------------------------------------------------------
[2003-01-10 04:51:27] maddog2k at maddog2k dot nl

Guess I'm the only one who'd like this behaviour :)

------------------------------------------------------------------------
[2001-11-15 13:12:05] maddog2k at maddog2k dot nl

The problem I ran into while using PHP as CGI-binary under for example Apache instead of mod_php, is
that you can't simply allow restrictive overrides of certain values.

If you for example put a 'php.ini' file in a directory, PHP will read that
file...completely ignoring the /usr/local/lib/php.ini

Let's say we have a malicious user who wants to upload files of 100MB, he could simply do that
by allowing this in his 'own' php.ini (post_max_size). I don't think this is a wanted
situation.

The restriction I'm using now (thanks to Mathieu), is by an edited php_ini.c that reads only
the php.ini from PHP_CONFIG_FILE_PATH. 

Why not using the same guidelines as with the ini_set() function ? Or an option in the
'default' .ini, to turn this behaviour on...:))

------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=14071&edit=1


Thread (1 message)

  • kalle@php.net
  • Unknown Message
    • kalle@php.net
« previous php.bugs (#211835) next »