Re: cvs: php4 /sapi/apache2filter apache_config.c php_apache.h sapi_apache2.c
| From: | Aaron Bannert | Date: | Fri, 19 Apr 2002 14:50:17 +0000 |
| Subject: | Re: cvs: php4 /sapi/apache2filter apache_config.c php_apache.h sapi_apache2.c | ||
| References: | 1 2 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-11236@lists.php.net to get a copy of this message | ||
On Fri, Apr 19, 2002 at 01:35:04AM -0400, Adam Maccabee Trachtenberg wrote:
> > PHPINIDir "conf"
> > # PHP will now look in the ServerRoot/conf directory for the php.ini file
>
> I get this really gross feeling knowing we would allow people to
> configure PHP to search for a php.ini file in a public web accessible
> globally readable directory.
The likelyhood of the php.ini file being in a publicly accessable
web directory is the same now as it was before.
> It just seems like it opens up the possibility of some security
> exploit. I know the file is readable on my system, and I don't know of
> any secret information stored in the file, and I know it's not linked
> to from anywhere. But... Why take a risk by putting settings in a
> place where people could find it?
I don't think there is any risk in this directive being misused either
maliciously or accidentally.
> Couldn't we just make it an absolute path? Or have it search the include_path?
What is the include_path, and how is it configured? By omitting the
directive from your httpd.conf you rely on the php default paths. This
means you'll get an absolute search path. The problem with absolute
paths is they prevent relocatable installation directories -- one build
only works in one place, and can't be reused on the same machine for a
different server.
-aaron