Bug #16039: File access is not limits by .htaccess for includes
| From: | mark at fregat dot net | Date: | Wed, 13 Mar 2002 12:17:43 +0000 |
| Subject: | Bug #16039: File access is not limits by .htaccess for includes | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-2378@lists.php.net to get a copy of this message | ||
From: mark@fregat.net
Operating system: FreeBSD 4.3
PHP version: 4.1.2
PHP Bug Type: Apache related
Bug description: File access is not limits by .htaccess for includes
I have PHP installed as an Apache module. When I try to
<? include /aaa/bbb/ccc.xxx ?>, access to /aaa/bbb/ccc.xxx
is granted without prompting for the login/password despite
the directory /aaa/bbb/ is password-protected by .htaccess
To my mind, any attempts of Apache access to .htaccess'ed
files should be limited according to .htaccess
--
Edit bug report at http://bugs.php.net/?id=16039&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=16039&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=16039&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=16039&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=16039&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=16039&r=support
Expected behavior: http://bugs.php.net/fix.php?id=16039&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=16039&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=16039&r=submittedtwice