#23232 [Asn->Csd]: safe_mode does not honor PHP_AUTH_* in apache2

From: Date: Wed, 16 Apr 2003 23:32:36 +0000
Subject: #23232 [Asn->Csd]: safe_mode does not honor PHP_AUTH_* in apache2
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-37782@lists.php.net to get a copy of this message
ID: 23232 Updated by: iliaa@php.net Reported By: raul at dias dot com dot br -Status: Assigned +Status: Closed Bug Type: Apache2 related Operating System: Linux PHP Version: 4.3.2RC1 Assigned To: moriyoshi New Comment: This bug has been fixed in CVS. In case this was a PHP problem, snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites in short time. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2003-04-16 18:26:48] moriyoshi@php.net This bug seems my fault. Raul: your reasoning seems valid. I'll fix the problem soon. ------------------------------------------------------------------------ [2003-04-16 16:30:52] raul at dias dot com dot br From my understanding, the only way to do a http authentication in php is not having an external authentication like apache's "AuthType". Does not matter if it is Basic or Digest. From http://www.php.net/manual/en/features.http-auth.php : --------------------- As of PHP 4.3.0, in order to prevent someone from writing a script which reveals the password for a page that was authenticated through a traditional external mechanism, the PHP_AUTH variables will not be set if external authentication is enabled for that particular page and safe mode is enabled. Regardless, REMOTE_USER can be used to identify the externally-authenticated user. So, you can use $_SERVER['REMOTE_USER']. -------------------- Also, IIRC, you cannot do http authentication twice at the same time and at the same page. I could be wrong on this. In the original patch, the line: -------------------- if (!PG(safe_mode) || (PG(safe_mode) && (auth_type = ap_auth_type(r)) && !strcasecmp(auth_type, "Basic"))) { --------------------- If safe_mode is on, the only way to see the PHP_AUTH* variables was by _having_ an external authentication different from Basic. In these case an malicious script would expose the USER + PASSWORD. So it still not possible to use a PHP pure http authentication. The solution is to enable the authentication if ap_auth_type(f->r) returns FALSE, as this mean that no external authentication took place. ------------------------------------------------------------------------ [2003-04-16 16:00:03] iliaa@php.net Is there a reason in your patch that you are not verifying that the authentication is basic? If my understanding is correct, then only basic authentication is allowed when safe_mode is enabled. ------------------------------------------------------------------------ [2003-04-16 15:54:36] raul at dias dot com dot br That patch did not work quite well. However it helped to rewrite a new one. This is the patch that worked: ------------------------------>8------------------------- diff -Nru php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c --- php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c 2003-03-05 13:12:41.000000000 -0300 +++ php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c 2003-04-16 12:33:00.000000000 -0300 @@ -367,6 +367,7 @@ { char *content_type; const char *auth; + const char *auth_type; PG(during_request_startup) = 0; SG(sapi_headers).http_response_code = 200; @@ -387,7 +388,7 @@ apr_table_unset(f->r->headers_out, "Expires"); apr_table_unset(f->r->headers_out, "ETag"); apr_table_unset(f->r->headers_in, "Connection"); - if (!PG(safe_mode)) { + if (!PG(safe_mode) || (PG(safe_mode) && !(auth_type = ap_auth_type(f->r)))) { auth = apr_table_get(f->r->headers_in, "Authorization"); php_handle_auth_data(auth TSRMLS_CC); } else { diff -Nru php-4.3.2RC1/sapi/apache2handler/sapi_apache2.c php-4.3.2RC1.patch/sapi/apache2handler/sapi_apache2.c --- php-4.3.2RC1/sapi/apache2handler/sapi_apache2.c 2003-03-10 00:17:04.000000000 -0300 +++ php-4.3.2RC1.patch/sapi/apache2handler/sapi_apache2.c 2003-04-16 12:34:21.000000000 -0300 @@ -409,6 +409,7 @@ { char *content_type; const char *auth; + const char *auth_type; SG(sapi_headers).http_response_code = 200; SG(request_info).content_type = apr_table_get(r->headers_in, "Content-Type"); @@ -426,7 +427,7 @@ apr_table_unset(r->headers_out, "Expires"); apr_table_unset(r->headers_out, "ETag"); apr_table_unset(r->headers_in, "Connection"); - if (!PG(safe_mode)) { + if (!PG(safe_mode) || (PG(safe_mode) && !(auth_type = ap_auth_type(r)))) { auth = apr_table_get(r->headers_in, "Authorization"); php_handle_auth_data(auth TSRMLS_CC); } else { --------------------------8<------------------------ This one now worked on a 4.3.1 php: ------------------------8<------------------- diff -Nru php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c --- php-4.3.2RC1/sapi/apache2filter/sapi_apache2.c 2003-03-05 13:12:41.000000000 -0300 +++ php-4.3.2RC1.patch/sapi/apache2filter/sapi_apache2.c 2003-04-16 12:33:00.000000000 -0300 @@ -367,6 +367,7 @@ { char *content_type; const char *auth; + const char *auth_type; PG(during_request_startup) = 0; SG(sapi_headers).http_response_code = 200; @@ -387,7 +388,7 @@ apr_table_unset(f->r->headers_out, "Expires"); apr_table_unset(f->r->headers_out, "ETag"); apr_table_unset(f->r->headers_in, "Connection"); - if (!PG(safe_mode)) { + if (!PG(safe_mode) || (PG(safe_mode) && !(auth_type = ap_auth_type(f->r)))) { auth = apr_table_get(f->r->headers_in, "Authorization"); php_handle_auth_data(auth TSRMLS_CC); } else { ----------------------------->8----------------------- I tested it with AuthType apache's authentication. ------------------------------------------------------------------------ [2003-04-15 22:52:34] raul at dias dot com dot br Thanks. I am compiling it, right now. Btw, shouldn't that be applyed to apache2filter/ dir too? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/23232 -- Edit this bug report at http://bugs.php.net/?id=23232&edit=1

« previous php.bugs (#37782) next »