#23232 [Opn->Asn]: safe_mode does not honor PHP_AUTH_* in apache2

From: Date: Wed, 16 Apr 2003 23:26:48 +0000
Subject: #23232 [Opn->Asn]: safe_mode does not honor PHP_AUTH_* in apache2
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-37781@lists.php.net to get a copy of this message
ID: 23232 Updated by: moriyoshi@php.net Reported By: raul at dias dot com dot br -Status: Open +Status: Assigned Bug Type: Apache2 related Operating System: Linux PHP Version: 4.3.2RC1 -Assigned To: +Assigned To: moriyoshi New Comment: This bug seems my fault. Raul: your reasoning seems valid. I'll fix the problem soon. Previous Comments: ------------------------------------------------------------------------ [2003-04-16 16:30:52] raul at dias dot com dot br From my understanding, the only way to do a http authentication in php is not having an external authentication like apache's "AuthType". Does not matter if it is Basic or Digest. From http://www.php.net/manual/en/features.http-auth.php : --------------------- As of PHP 4.3.0, in order to prevent someone from writing a script which reveals the password for a page that was authenticated through a traditional external mechanism, the PHP_AUTH variables will not be set if external authentication is enabled for that particular page and safe mode is enabled. Regardless, REMOTE_USER can be used to identify the externally-authenticated user. So, you can use $_SERVER['REMOTE_USER']. -------------------- Also, IIRC, you cannot do http authentication twice at the same time and at the same page. I could be wrong on this. In the original patch, the line: -------------------- if (!PG(safe_mode) || (PG(safe_mode) && (auth_type = ap_auth_type(r)) && !strcasecmp(auth_type, "Basic"))) { --------------------- If safe_mode is on, the only way to see the PHP_AUTH* variables was by _having_ an external authentication different from Basic. In these case an malicious script would expose the USER + PASSWORD. So it still not possible to use a PHP pure http authentication. The solution is to enable the authentication if ap_auth_type(f->r) returns FALSE, as this mean that no external authentication took place. ------------------------------------------------------------------------ [2003-04-16 16:00:03] iliaa@php.net Is there a reason in your patch that you are not verifying that the authentication is basic? If my understanding is correct, then only basic authentication is allowed when safe_mode is enabled. ------------------------------------------------------------------------ [2003-04-16 15:54:36] raul at dias dot com dot br That patch did not work quite well. However it helped to rewrite a new one. This is the patch that worked: ------------------------------>8------------------------- diff -Nru php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c --- php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c 2003-03-05 13:12:41.000000000 -0300 +++ php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c 2003-04-16 12:33:00.000000000 -0300 @@ -367,6 +367,7 @@ { char *content_type; const char *auth; + const char *auth_type; PG(during_request_startup) = 0; SG(sapi_headers).http_response_code = 200; @@ -387,7 +388,7 @@ apr_table_unset(f->r->headers_out, "Expires"); apr_table_unset(f->r->headers_out, "ETag"); apr_table_unset(f->r->headers_in, "Connection"); - if (!PG(safe_mode)) { + if (!PG(safe_mode) || (PG(safe_mode) && !(auth_type = ap_auth_type(f->r)))) { auth = apr_table_get(f->r->headers_in, "Authorization"); php_handle_auth_data(auth TSRMLS_CC); } else { diff -Nru php-4.3.2RC1/sapi/apache2handler/sapi_apache2.c php-4.3.2RC1.patch/sapi/apache2handler/sapi_apache2.c --- php-4.3.2RC1/sapi/apache2handler/sapi_apache2.c 2003-03-10 00:17:04.000000000 -0300 +++ php-4.3.2RC1.patch/sapi/apache2handler/sapi_apache2.c 2003-04-16 12:34:21.000000000 -0300 @@ -409,6 +409,7 @@ { char *content_type; const char *auth; + const char *auth_type; SG(sapi_headers).http_response_code = 200; SG(request_info).content_type = apr_table_get(r->headers_in, "Content-Type"); @@ -426,7 +427,7 @@ apr_table_unset(r->headers_out, "Expires"); apr_table_unset(r->headers_out, "ETag"); apr_table_unset(r->headers_in, "Connection"); - if (!PG(safe_mode)) { + if (!PG(safe_mode) || (PG(safe_mode) && !(auth_type = ap_auth_type(r)))) { auth = apr_table_get(r->headers_in, "Authorization"); php_handle_auth_data(auth TSRMLS_CC); } else { --------------------------8<------------------------ This one now worked on a 4.3.1 php: ------------------------8<------------------- diff -Nru php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c --- php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c 2003-03-05 13:12:41.000000000 -0300 +++ php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c 2003-04-16 12:33:00.000000000 -0300 @@ -367,6 +367,7 @@ { char *content_type; const char *auth; + const char *auth_type; PG(during_request_startup) = 0; SG(sapi_headers).http_response_code = 200; @@ -387,7 +388,7 @@ apr_table_unset(f->r->headers_out, "Expires"); apr_table_unset(f->r->headers_out, "ETag"); apr_table_unset(f->r->headers_in, "Connection"); - if (!PG(safe_mode)) { + if (!PG(safe_mode) || (PG(safe_mode) && !(auth_type = ap_auth_type(f->r)))) { auth = apr_table_get(f->r->headers_in, "Authorization"); php_handle_auth_data(auth TSRMLS_CC); } else { ----------------------------->8----------------------- I tested it with AuthType apache's authentication. ------------------------------------------------------------------------ [2003-04-15 22:52:34] raul at dias dot com dot br Thanks. I am compiling it, right now. Btw, shouldn't that be applyed to apache2filter/ dir too? ------------------------------------------------------------------------ [2003-04-15 22:14:44] iliaa@php.net Please try the patch at: http://bb.prohost.org/ap2.txt and let me know if it fixes the problem. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/23232 -- Edit this bug report at http://bugs.php.net/?id=23232&edit=1

« previous php.bugs (#37781) next »