#23232 [Opn->Asn]: safe_mode does not honor PHP_AUTH_* in apache2
| From: | moriyoshi@php.net | Date: | Wed, 16 Apr 2003 23:26:48 +0000 |
| Subject: | #23232 [Opn->Asn]: safe_mode does not honor PHP_AUTH_* in apache2 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-37781@lists.php.net to get a copy of this message | ||
ID: 23232
Updated by: moriyoshi@php.net
Reported By: raul at dias dot com dot br
-Status: Open
+Status: Assigned
Bug Type: Apache2 related
Operating System: Linux
PHP Version: 4.3.2RC1
-Assigned To:
+Assigned To: moriyoshi
New Comment:
This bug seems my fault.
Raul: your reasoning seems valid. I'll fix the problem soon.
Previous Comments:
------------------------------------------------------------------------
[2003-04-16 16:30:52] raul at dias dot com dot br
From my understanding, the only way to do a http
authentication in php is not having an external
authentication like apache's "AuthType".
Does not matter if it is Basic or Digest.
From http://www.php.net/manual/en/features.http-auth.php
:
---------------------
As of PHP 4.3.0, in order to prevent someone from writing a script
which reveals the password for a page that was authenticated through a
traditional external mechanism, the PHP_AUTH variables will not be set
if external authentication is enabled for that particular page and safe
mode is enabled. Regardless, REMOTE_USER can be used to identify the
externally-authenticated user. So, you can use
$_SERVER['REMOTE_USER'].
--------------------
Also, IIRC, you cannot do http authentication twice at the
same time and at the same page. I could be wrong on this.
In the original patch, the line:
--------------------
if (!PG(safe_mode) || (PG(safe_mode) && (auth_type = ap_auth_type(r))
&& !strcasecmp(auth_type, "Basic"))) {
---------------------
If safe_mode is on, the only way to see the PHP_AUTH*
variables was by _having_ an external authentication
different from Basic.
In these case an malicious script would expose the
USER + PASSWORD.
So it still not possible to use a PHP pure http
authentication.
The solution is to enable the authentication if ap_auth_type(f->r)
returns FALSE, as this mean that
no external authentication took place.
------------------------------------------------------------------------
[2003-04-16 16:00:03] iliaa@php.net
Is there a reason in your patch that you are not verifying that the
authentication is basic? If my understanding is correct, then only
basic authentication is allowed when safe_mode is enabled.
------------------------------------------------------------------------
[2003-04-16 15:54:36] raul at dias dot com dot br
That patch did not work quite well.
However it helped to rewrite a new one.
This is the patch that worked:
------------------------------>8-------------------------
diff -Nru php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c
php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c
--- php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c 2003-03-05
13:12:41.000000000 -0300
+++ php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c 2003-04-16
12:33:00.000000000 -0300
@@ -367,6 +367,7 @@
{
char *content_type;
const char *auth;
+ const char *auth_type;
PG(during_request_startup) = 0;
SG(sapi_headers).http_response_code = 200;
@@ -387,7 +388,7 @@
apr_table_unset(f->r->headers_out, "Expires");
apr_table_unset(f->r->headers_out, "ETag");
apr_table_unset(f->r->headers_in, "Connection");
- if (!PG(safe_mode)) {
+ if (!PG(safe_mode) || (PG(safe_mode) && !(auth_type =
ap_auth_type(f->r)))) {
auth = apr_table_get(f->r->headers_in, "Authorization");
php_handle_auth_data(auth TSRMLS_CC);
} else {
diff -Nru php-4.3.2RC1/sapi/apache2handler/sapi_apache2.c
php-4.3.2RC1.patch/sapi/apache2handler/sapi_apache2.c
--- php-4.3.2RC1/sapi/apache2handler/sapi_apache2.c 2003-03-10
00:17:04.000000000 -0300
+++ php-4.3.2RC1.patch/sapi/apache2handler/sapi_apache2.c 2003-04-16
12:34:21.000000000 -0300
@@ -409,6 +409,7 @@
{
char *content_type;
const char *auth;
+ const char *auth_type;
SG(sapi_headers).http_response_code = 200;
SG(request_info).content_type = apr_table_get(r->headers_in,
"Content-Type");
@@ -426,7 +427,7 @@
apr_table_unset(r->headers_out, "Expires");
apr_table_unset(r->headers_out, "ETag");
apr_table_unset(r->headers_in, "Connection");
- if (!PG(safe_mode)) {
+ if (!PG(safe_mode) || (PG(safe_mode) && !(auth_type =
ap_auth_type(r)))) {
auth = apr_table_get(r->headers_in, "Authorization");
php_handle_auth_data(auth TSRMLS_CC);
} else {
--------------------------8<------------------------
This one now worked on a 4.3.1 php:
------------------------8<-------------------
diff -Nru php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c
php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c
--- php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c 2003-03-05
13:12:41.000000000 -0300
+++ php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c 2003-04-16
12:33:00.000000000 -0300
@@ -367,6 +367,7 @@
{
char *content_type;
const char *auth;
+ const char *auth_type;
PG(during_request_startup) = 0;
SG(sapi_headers).http_response_code = 200;
@@ -387,7 +388,7 @@
apr_table_unset(f->r->headers_out, "Expires");
apr_table_unset(f->r->headers_out, "ETag");
apr_table_unset(f->r->headers_in, "Connection");
- if (!PG(safe_mode)) {
+ if (!PG(safe_mode) || (PG(safe_mode) && !(auth_type =
ap_auth_type(f->r)))) {
auth = apr_table_get(f->r->headers_in, "Authorization");
php_handle_auth_data(auth TSRMLS_CC);
} else {
----------------------------->8-----------------------
I tested it with AuthType apache's authentication.
------------------------------------------------------------------------
[2003-04-15 22:52:34] raul at dias dot com dot br
Thanks.
I am compiling it, right now.
Btw, shouldn't that be applyed to apache2filter/ dir too?
------------------------------------------------------------------------
[2003-04-15 22:14:44] iliaa@php.net
Please try the patch at:
http://bb.prohost.org/ap2.txt
and let me know if it fixes the problem.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/23232
--
Edit this bug report at http://bugs.php.net/?id=23232&edit=1