Re: cvs: php4 /sapi/apache2filter apache_config.c php_apache.h sapi_apache2.c

From: Date: Fri, 19 Apr 2002 05:35:04 +0000
Subject: Re: cvs: php4 /sapi/apache2filter apache_config.c php_apache.h sapi_apache2.c
References: 1  Groups: php.cvs 
Request: Send a blank email to php-cvs+get-11211@lists.php.net to get a copy of this message
On Thu, 18 Apr 2002, Aaron Bannert wrote: > aaron Thu Apr 18 18:10:58 2002 EDT > > Modified files: > /php4/sapi/apache2filter sapi_apache2.c php_apache.h > apache_config.c > Log: > This patch implements a new Apache2 directive called PHPINIDir that > allows the specification of the php.ini directory from within the Apache > configuration. If left unset, the default is to defer to the hard-coded > php paths. When set, the supplied path is made relative to Apache's > internal ServerRoot setting. > > Example: > PHPINIDir "conf" > # PHP will now look in the ServerRoot/conf directory for the php.ini file I get this really gross feeling knowing we would allow people to configure PHP to search for a php.ini file in a public web accessible globally readable directory. It just seems like it opens up the possibility of some security exploit. I know the file is readable on my system, and I don't know of any secret information stored in the file, and I know it's not linked to from anywhere. But... Why take a risk by putting settings in a place where people could find it? Couldn't we just make it an absolute path? Or have it search the include_path? -adam -- adam maccabee trachtenberg adam@trachtenberg.com

« previous php.cvs (#11211) next »