Req->Bug #37247 [Opn->Fbk]: Option to turn off Apache subrequests for PATH_TRANSLATED

From: Date: Sat, 05 May 2018 18:09:14 +0000
Subject: Req->Bug #37247 [Opn->Fbk]: Option to turn off Apache subrequests for PATH_TRANSLATED
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215069@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=37247&edit=1 ID: 37247 Updated by: requinix@php.net Reported by: php_public at macfreek dot nl Summary: Option to turn off Apache subrequests for PATH_TRANSLATED -Status: Open +Status: Feedback -Type: Feature/Change Request +Type: Bug -Package: Feature/Change Request +Package: Apache related Operating System: Linux PHP Version: 5.1.2 Block user comment: N Private report: N New Comment: Anyone know and/or care if this is still the case? I assume it's from mod_php. Previous Comments: ------------------------------------------------------------------------ [2006-04-29 21:28:30] php_public at macfreek dot nl Description: ------------ The CGI 1.1 specification specifies that a request for http://example.com/test/test.php/argument where test.php is a PHP script Would define PHP_INFO: /argument PATH_TRANSLATED: /www/htdocs/argument (asuming that /www/htdocs is the on the document root) Apache correctly set these variables, and PHP lists then in the _SERVER variable, and passes them to the test.php script. To my surprise, PHP not only executes test.php, but aparently also does an Apache subrequest for /argument. This request is not displayed in the access log. However, the subrequest can be seen in the error log if / is disallowed ("deny from all" in the .htaccess file), and allowed in /test/ ("allow from all in the /test/.htacess file). Reproduce code: --------------- See above. Files in the document root, with content: /.htaccess: Order allow,deny /test/.htaccess: allow from all /test/test.php: <p>PHP file</p> /test/test.txt: <p>Text file</p> Expected result: ---------------- I would expect that a call to /test/test.php would display the contents of the file, pass the CGI variables, and just do that, and nothing more. Actual result: -------------- A request to /test/test.php/argument displays the files content "<p>PHP file</p>", as expected. However, the Apache error log also shows "client denied by server configuration: /www/htdocs/argument, referer: http://www.example.com/test/test.php/argument" I did not expect this subrequest; it does not seem necessary to make the request. In fact, if the file does exists, and is accessible, the output of the request does not change. So the subrequest seems spurious to me. Feature request: I recommend to remove the Apache subrequest (or whatever it exactly is). If the subrequest has a purpose, I'm curious to hear the reason, and I recommend instead to add an option to disable it. Note that the --disable-path-info-check configuration parameter is not what I want: that completely disables the requests with PATH_INFO. I just don't want PHP or Apache to make a request to it. Regression notes: A request to /test/test.txt/argument gives and error "404 No such file "/test/test.txt/argument". No other error is logged. This indicated that indeed the fact that PHP makes the Apache subrequest, and not Apache itself. I found this behaviour when running MediaWiki, which makes use of these kind of URL's in the form of /wiki/index.php/Article. I'm running Apache 2.0.54 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=37247&edit=1

« previous php.bugs (#215069) next »