Re: cvs: php4 /sapi/apache2filter apache_config.c php_apache.h sapi_apache2.c

From: Date: Fri, 19 Apr 2002 06:39:57 +0000
Subject: Re: cvs: php4 /sapi/apache2filter apache_config.c php_apache.h sapi_apache2.c
References: 1  Groups: php.cvs 
Request: Send a blank email to php-cvs+get-11216@lists.php.net to get a copy of this message
On Fri, 2002-04-19 at 07:35, Adam Maccabee Trachtenberg wrote: > On Thu, 18 Apr 2002, Aaron Bannert wrote: > > > aaron Thu Apr 18 18:10:58 2002 EDT > > > > Modified files: > > /php4/sapi/apache2filter sapi_apache2.c php_apache.h > > apache_config.c > > Log: > > This patch implements a new Apache2 directive called PHPINIDir that > > allows the specification of the php.ini directory from within the Apache > > configuration. If left unset, the default is to defer to the hard-coded > > php paths. When set, the supplied path is made relative to Apache's > > internal ServerRoot setting. > > > > Example: > > PHPINIDir "conf" > > # PHP will now look in the ServerRoot/conf directory for the php.ini file > > I get this really gross feeling knowing we would allow people to > configure PHP to search for a php.ini file in a public web accessible > globally readable directory. > > It just seems like it opens up the possibility of some security > exploit. I know the file is readable on my system, and I don't know of > any secret information stored in the file, and I know it's not linked > to from anywhere. But... Why take a risk by putting settings in a > place where people could find it? > > Couldn't we just make it an absolute path? Or have it search the include_path? Apache is already letting you configure all kinds of files (I guess that includes password files) relative to the server root, that would be more serious to have exposed than php.ini. IMHO it makes more sense to be consistent with the way Apache specifies other config files. - Stig

« previous php.cvs (#11216) next »