Re: cvs: php4 /sapi/apache2filter apache_config.c php_apache.h sapi_apache2.c

From: Date: Fri, 19 Apr 2002 14:50:17 +0000
Subject: Re: cvs: php4 /sapi/apache2filter apache_config.c php_apache.h sapi_apache2.c
References: 1 2  Groups: php.cvs 
Request: Send a blank email to php-cvs+get-11236@lists.php.net to get a copy of this message
On Fri, Apr 19, 2002 at 01:35:04AM -0400, Adam Maccabee Trachtenberg wrote: > > PHPINIDir "conf" > > # PHP will now look in the ServerRoot/conf directory for the php.ini file > > I get this really gross feeling knowing we would allow people to > configure PHP to search for a php.ini file in a public web accessible > globally readable directory. The likelyhood of the php.ini file being in a publicly accessable web directory is the same now as it was before. > It just seems like it opens up the possibility of some security > exploit. I know the file is readable on my system, and I don't know of > any secret information stored in the file, and I know it's not linked > to from anywhere. But... Why take a risk by putting settings in a > place where people could find it? I don't think there is any risk in this directive being misused either maliciously or accidentally. > Couldn't we just make it an absolute path? Or have it search the include_path? What is the include_path, and how is it configured? By omitting the directive from your httpd.conf you rely on the php default paths. This means you'll get an absolute search path. The problem with absolute paths is they prevent relocatable installation directories -- one build only works in one place, and can't be reused on the same machine for a different server. -aaron

« previous php.cvs (#11236) next »