[php-src] Issue #13110: Add option to hide Environment Variables from $_SERVER
| From: | ggedde | Date: | Tue, 09 Jan 2024 21:12:13 +0000 |
| Subject: | [php-src] Issue #13110: Add option to hide Environment Variables from $_SERVER | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-246207@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/13110
Author: ggedde
### Description
I am looking for a way to hide Environment Variables from $_SERVER or from all Global Arrays.
I would prefer to secure my environment variables as much as possible and make them explicit when
using.
I only require getenv('my_env_var');
I do not want or need $_SERVER['my_env_var'] or $_ENV['my_env_var'].
There are many third-party tools and libraries that might expose $_SERVER in logs or debugging. Also
if the code is compromised dumping $_SERVER is very easy. This could be mitigated by encrypting
Environment Variables, but I would also like to make accessing them very explicit.
Currently I can set
clear_env to yes and change variables_order to
"GPCS" and ignore "E" to remove $_ENV, but I can't remove "S" as
that is needed for REMOTE_ADDR, etc.
It would be nice to have another php config option to do that and have that option accessible from
php-fpm config as well like clear_env or variables_order
Maybe something like expose_env. Default is yes, but can be set to no.
no should remove it from $_SERVER as well as $_ENV or any other Global data.
Bonus points if no can also remove it from, errors, functions (like debug_backtrace),
etc.
Thanks