cvs: php4 / NEWS php.ini-dist php.ini-optimized php.ini-recommended

From: Date: Sat, 11 Aug 2001 15:22:56 +0000
Subject: cvs: php4 / NEWS php.ini-dist php.ini-optimized php.ini-recommended
Groups: php.cvs 
Request: Send a blank email to php-cvs+get-6737@lists.php.net to get a copy of this message
zeev Sat Aug 11 11:22:56 2001 EDT Removed files: /php4 php.ini-optimized Modified files: /php4 NEWS php.ini-dist php.ini-recommended Log: Start pushing register_globals annihilation Index: php4/NEWS diff -u php4/NEWS:1.731 php4/NEWS:1.732 --- php4/NEWS:1.731 Thu Aug 9 20:10:30 2001 +++ php4/NEWS Sat Aug 11 11:22:56 2001 @@ -1,8 +1,11 @@ PHP 4.0 NEWS ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| ?? ??? 200?, Version 4.0.7-dev +- Replaced php.ini-optimized with php.ini-recommended. As the name implies, + it's warmly recommended to use this file as the basis for your PHP + configuration, rather than php.ini-dist. (Zeev) - Restore xpath_eval() and php_xpathptr_eval() for 4.0.7. There - are still some known leaks. + are still some known leaks. (Joey) - Added import_request_variables(), to allow users to safely import form variables to the global scope (Zeev) - Introduced a new $_REQUEST array, which includes any GET, POST or COOKIE Index: php4/php.ini-dist diff -u php4/php.ini-dist:1.91 php4/php.ini-dist:1.92 --- php4/php.ini-dist:1.91 Fri Aug 10 22:53:57 2001 +++ php4/php.ini-dist Sat Aug 11 11:22:56 2001 @@ -1,5 +1,15 @@ [PHP] -; $Id: php.ini-dist,v 1.91 2001/08/11 02:53:57 avsm Exp $ + +;;;;;;;;;;; +; WARNING ; +;;;;;;;;;;; +; This is the default settings file for new PHP installations. +; By default, PHP installs itself with a configuration suitable for +; development purposes, and *NOT* for production purposes. +; For several security-oriented considerations that should be taken +; before going online with your site, please consult php.ini-recommended +; and http://php.net/manual/en/security.php. + ;;;;;;;;;;;;;;;;;;; ; About this file ; Index: php4/php.ini-recommended diff -u php4/php.ini-recommended:1.45 php4/php.ini-recommended:1.46 --- php4/php.ini-recommended:1.45 Fri Aug 10 22:53:56 2001 +++ php4/php.ini-recommended Sat Aug 11 11:22:56 2001 @@ -4,7 +4,11 @@ ; About this file ; ;;;;;;;;;;;;;;;;;;; ; -; This is the 'optimized', PHP 4-style version of the php.ini-dist file. +; This is the recommended, PHP 4-style version of the php.ini-dist file. It +; sets some non standard settings, that make PHP more efficient and more secure. +; The price is that with these settings, PHP may be incompatible with some +; applications. Using this file is warmly recommended for production sites. +; ; For general information about the php.ini file, please consult the php.ini-dist ; file, included in your PHP distribution. ; @@ -14,26 +18,44 @@ ; PHP 3. Please make sure you read what's different, and modify your scripts ; accordingly, if you decide to use this file instead. ; -; - allow_call_time_pass_reference = Off -; It's not possible to decide to force a variable to be passed by reference -; when calling a function. The PHP 4 style to do this is by making the -; function require the relevant argument by reference. -; - register_globals = Off +; - register_globals = Off [Security, Performance] ; Global variables are no longer registered for input data (POST, GET, cookies, ; environment and other server variables). Instead of using $foo, you must use -; $HTTP_POST_VARS["foo"], $HTTP_GET_VARS["foo"], $HTTP_COOKIE_VARS["foo"], -; $HTTP_ENV_VARS["foo"] or $HTTP_SERVER_VARS["foo"], depending on which kind -; of input source you're expecting 'foo' to come from. -; - register_argc_argv = Off +; you can use $_REQUEST["foo"] (includes any variable that arrives through the +; request, namely, POST, GET and cookie variables), or use one of the specific +; $_GET["foo"], $_POST["foo"], $_COOKIE["foo"] or $_FILES["foo"], depending +; on where the input originates. +; Note that register_globals is going to be depracated (i.e., turned off by +; default) in the next version of PHP, because it often leads to security bugs. +; Read http://php.net/manual/en/security.registerglobals.php for further +; information. +; - display_errors = Off [Security] +; With this directive set to off, errors that occur during the execution of +; scripts will no longer be displayed as a part of the script output, and thus, +; will no longer be exposed to remote users. With some errors, the error message +; content may expose information about your script, web server, or database +; server that may be exploitable for hacking. Production sites should have this +; directive set to off. +; - log_errors = On [Security] +; This directive complements the above one. Any errors that occur during the +; execution of your script will be logged (typically, to your server's error log, +; but can be configured in several ways). Along with setting display_errors to off, +; this setup gives you the ability to fully understand what may have gone wrong, +; without exposing any sensitive information to remote users. +; - register_argc_argv = Off [Performance] ; Disables registration of the somewhat redundant $argv and $argc global ; variables. -; - magic_quotes_gpc = Off +; - magic_quotes_gpc = Off [Performance] ; Input data is no longer escaped with slashes so that it can be sent into ; SQL databases without further manipulation. Instead, you should use the ; function addslashes() on each input element you wish to send to a database. -; - variables_order = "GPCS" +; - variables_order = "GPCS" [Performance] ; The environment variables are not hashed into the $HTTP_ENV_VARS[]. To access ; environment variables, you can use getenv() instead. +; - allow_call_time_pass_reference = Off [Code cleanliness] +; It's not possible to decide to force a variable to be passed by reference +; when calling a function. The PHP 4 style to do this is by making the +; function require the relevant argument by reference. ;;;;;;;;;;;;;;;;;;;; @@ -167,7 +189,7 @@ ; error_reporting = E_ALL & ~E_NOTICE ; show all errors, except for notices ; error_reporting = E_COMPILE_ERROR|E_ERROR|E_CORE_ERROR ; show only errors error_reporting = E_ALL & ~E_NOTICE ; Show all errors except for notices -display_errors = On ; Print out errors (as a part of the output) +display_errors = Off ; Print out errors (as a part of the output) ; For production web sites, you're strongly encouraged ; to turn this feature off, and use error logging instead (see below). ; Keeping display_errors enabled on a production web site may reveal @@ -177,7 +199,7 @@ ; PHP's startup sequence are not displayed. It's strongly ; recommended to keep display_startup_errors off, except for ; when debugging. -log_errors = Off ; Log errors into a log file (server-specific log, stderr, or error_log (below)) +log_errors = On ; Log errors into a log file (server-specific log, stderr, or error_log (below)) ; As stated above, you're strongly advised to use error logging in place of ; error displaying on production web sites. track_errors = Off ; Store the last error/warning message in $php_errormsg (boolean)

« previous php.cvs (#6737) next »