Edit report at https://bugs.php.net/bug.php?id=14071&edit=1
ID: 14071
Updated by: kalle@php.net
Reported by: maddog2k at maddog2k dot nl
Summary: 'admin-values' php.ini also for CGI-binary
-Status: Open
+Status: Closed
Type: Feature/Change Request
Package: PHP options/info functions
Operating System: Linux/FreeBSD
PHP Version: 4.0.6
-Assigned To:
+Assigned To: kalle
Block user comment: N
Private report: N
New Comment:
I'm not sure at what point the php-cgi -c option was introduced, but it seems more reasonable
to simply supply the CGI SAPI of PHP with a specific php.ini file using php-cgi -c /path/to/php.ini
Please re-open if this still is an issue with PHP7
Previous Comments:
------------------------------------------------------------------------
[2003-01-10 04:51:27] maddog2k at maddog2k dot nl
Guess I'm the only one who'd like this behaviour :)
------------------------------------------------------------------------
[2001-11-15 13:12:05] maddog2k at maddog2k dot nl
The problem I ran into while using PHP as CGI-binary under for example Apache instead of mod_php, is
that you can't simply allow restrictive overrides of certain values.
If you for example put a 'php.ini' file in a directory, PHP will read that
file...completely ignoring the /usr/local/lib/php.ini
Let's say we have a malicious user who wants to upload files of 100MB, he could simply do that
by allowing this in his 'own' php.ini (post_max_size). I don't think this is a wanted
situation.
The restriction I'm using now (thanks to Mathieu), is by an edited php_ini.c that reads only
the php.ini from PHP_CONFIG_FILE_PATH.
Why not using the same guidelines as with the ini_set() function ? Or an option in the
'default' .ini, to turn this behaviour on...:))
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=14071&edit=1