#23232 [Fbk->Opn]: safe_mode does not honor PHP_AUTH_* in apache2
ID: 23232
User updated by: raul at dias dot com dot br
Reported By: raul at dias dot com dot br
-Status: Feedback
+Status: Open
Bug Type: Apache2 related
Operating System: Linux
PHP Version: 4.3.2RC1
New Comment:
Thanks.
I am compiling it, right now.
Btw, shouldn't that be applyed to apache2filter/ dir too?
Previous Comments:
------------------------------------------------------------------------
[2003-04-15 22:14:44] iliaa@php.net
Please try the patch at:
http://bb.prohost.org/ap2.txt
and let me know if it fixes the problem.
------------------------------------------------------------------------
[2003-04-15 21:22:15] raul at dias dot com dot br
When safe_mode is on PHP_AUTH_USER and PHP_AUTH_PW should set
to NULL only if there is an external authentication.
If there is no external authentication these variables should
NOT be set to NULL.
In APACHE 1.x code this is done by checking the authtype(r)
variable, which means that there is an authentication set in
either httpd.conf or a .htaccess file.
In APACHE 2.x code, there is no such checking.
If safe_mode is on those variables are NULLed without any
other type of checking for an external authentication.
I am not sure if this is a BUG or a "FEATURE", but because
of the lack of information about this in the code or
documentation, I am assuming this is a bug.
I am still not familiar with APACHE 2.x API or all
its features to suggest the best way to fix this or patch it.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23232&edit=1
Thread (8 messages)