RE: [PHP-CVS] cvs: php4 / NEWS php.ini-dist php.ini-optimized php.ini-recommended

From: Date: Mon, 13 Aug 2001 21:09:29 +0000
Subject: RE: [PHP-CVS] cvs: php4 / NEWS php.ini-dist php.ini-optimized php.ini-recommended
References: 1  Groups: php.cvs 
Request: Send a blank email to php-cvs+get-6787@lists.php.net to get a copy of this message
Correct me if I´m wrong, I´m talking from an Apache point of view. A short question about this: > -; - variables_order = "GPCS" > +; - variables_order = "GPCS" [Performance] is "S" really needed? I´ve lived without it for quite some time, since all those variables can be fetched with getenv(). Marten. > -----Original Message----- > From: Zeev Suraski [mailto:zeev@zend.com] > Sent: Saturday, August 11, 2001 5:23 PM > To: php-cvs@lists.php.net > Subject: [PHP-CVS] cvs: php4 / NEWS php.ini-dist php.ini-optimized > php.ini-recommended > > > zeev Sat Aug 11 11:22:56 2001 EDT > > Removed files: > /php4 php.ini-optimized > > Modified files: > /php4 NEWS php.ini-dist php.ini-recommended > Log: > Start pushing register_globals annihilation > > > Index: php4/NEWS > diff -u php4/NEWS:1.731 php4/NEWS:1.732 > --- php4/NEWS:1.731 Thu Aug 9 20:10:30 2001 > +++ php4/NEWS Sat Aug 11 11:22:56 2001 > @@ -1,8 +1,11 @@ > PHP 4.0 > NEWS > > |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| > ||||||||||||| > ?? ??? 200?, Version 4.0.7-dev > +- Replaced php.ini-optimized with php.ini-recommended. As the > name implies, > + it's warmly recommended to use this file as the basis for your PHP > + configuration, rather than php.ini-dist. (Zeev) > - Restore xpath_eval() and php_xpathptr_eval() for 4.0.7. There > - are still some known leaks. > + are still some known leaks. (Joey) > - Added import_request_variables(), to allow users to safely import form > variables to the global scope (Zeev) > - Introduced a new $_REQUEST array, which includes any GET, POST > or COOKIE > Index: php4/php.ini-dist > diff -u php4/php.ini-dist:1.91 php4/php.ini-dist:1.92 > --- php4/php.ini-dist:1.91 Fri Aug 10 22:53:57 2001 > +++ php4/php.ini-dist Sat Aug 11 11:22:56 2001 > @@ -1,5 +1,15 @@ > [PHP] > -; $Id: php.ini-dist,v 1.91 2001/08/11 02:53:57 avsm Exp $ > + > +;;;;;;;;;;; > +; WARNING ; > +;;;;;;;;;;; > +; This is the default settings file for new PHP installations. > +; By default, PHP installs itself with a configuration suitable for > +; development purposes, and *NOT* for production purposes. > +; For several security-oriented considerations that should be taken > +; before going online with your site, please consult php.ini-recommended > +; and http://php.net/manual/en/security.php. > + > > ;;;;;;;;;;;;;;;;;;; > ; About this file ; > Index: php4/php.ini-recommended > diff -u php4/php.ini-recommended:1.45 php4/php.ini-recommended:1.46 > --- php4/php.ini-recommended:1.45 Fri Aug 10 22:53:56 2001 > +++ php4/php.ini-recommended Sat Aug 11 11:22:56 2001 > @@ -4,7 +4,11 @@ > ; About this file ; > ;;;;;;;;;;;;;;;;;;; > ; > -; This is the 'optimized', PHP 4-style version of the php.ini-dist file. > +; This is the recommended, PHP 4-style version of the > php.ini-dist file. It > +; sets some non standard settings, that make PHP more efficient > and more secure. > +; The price is that with these settings, PHP may be incompatible > with some > +; applications. Using this file is warmly recommended for > production sites. > +; > ; For general information about the php.ini file, please consult > the php.ini-dist > ; file, included in your PHP distribution. > ; > @@ -14,26 +18,44 @@ > ; PHP 3. Please make sure you read what's different, and modify > your scripts > ; accordingly, if you decide to use this file instead. > ; > -; - allow_call_time_pass_reference = Off > -; It's not possible to decide to force a variable to be > passed by reference > -; when calling a function. The PHP 4 style to do this is by > making the > -; function require the relevant argument by reference. > -; - register_globals = Off > +; - register_globals = Off [Security, Performance] > ; Global variables are no longer registered for input data > (POST, GET, cookies, > ; environment and other server variables). Instead of using > $foo, you must use > -; $HTTP_POST_VARS["foo"], $HTTP_GET_VARS["foo"], > $HTTP_COOKIE_VARS["foo"], > -; $HTTP_ENV_VARS["foo"] or $HTTP_SERVER_VARS["foo"], > depending on which kind > -; of input source you're expecting 'foo' to come from. > -; - register_argc_argv = Off > +; you can use $_REQUEST["foo"] (includes any variable that > arrives through the > +; request, namely, POST, GET and cookie variables), or use > one of the specific > +; $_GET["foo"], $_POST["foo"], $_COOKIE["foo"] or > $_FILES["foo"], depending > +; on where the input originates. > +; Note that register_globals is going to be depracated > (i.e., turned off by > +; default) in the next version of PHP, because it often > leads to security bugs. > +; Read http://php.net/manual/en/security.registerglobals.php;sÌ 9€Wì > f�:©¸ > for further > +; information. > +; - display_errors = Off [Security] > +; With this directive set to off, errors that occur during > the execution of > +; scripts will no longer be displayed as a part of the > script output, and thus, > +; will no longer be exposed to remote users. With some > errors, the error message > +; content may expose information about your script, web > server, or database > +; server that may be exploitable for hacking. Production > sites should have this > +; directive set to off. > +; - log_errors = On [Security] > +; This directive complements the above one. Any errors that > occur during the > +; execution of your script will be logged (typically, to > your server's error log, > +; but can be configured in several ways). Along with > setting display_errors to off, > +; this setup gives you the ability to fully understand what > may have gone wrong, > +; without exposing any sensitive information to remote users. > +; - register_argc_argv = Off [Performance] > ; Disables registration of the somewhat redundant $argv and > $argc global > ; variables. > -; - magic_quotes_gpc = Off > +; - magic_quotes_gpc = Off [Performance] > ; Input data is no longer escaped with slashes so that it > can be sent into > ; SQL databases without further manipulation. Instead, you > should use the > ; function addslashes() on each input element you wish to > send to a database. > -; - variables_order = "GPCS" > +; - variables_order = "GPCS" [Performance] > ; The environment variables are not hashed into the > $HTTP_ENV_VARS[]. To access > ; environment variables, you can use getenv() instead. > +; - allow_call_time_pass_reference = Off [Code cleanliness] > +; It's not possible to decide to force a variable to be > passed by reference > +; when calling a function. The PHP 4 style to do this is by > making the > +; function require the relevant argument by reference. > > > ;;;;;;;;;;;;;;;;;;;; > @@ -167,7 +189,7 @@ > ; error_reporting = E_ALL & ~E_NOTICE > ; show all errors, except for notices > ; error_reporting = E_COMPILE_ERROR|E_ERROR|E_CORE_ERROR ; > show only errors > error_reporting = E_ALL & ~E_NOTICE ; > Show all errors except for notices > -display_errors = On ; Print out errors (as a > part of the output) > +display_errors = Off ; Print out errors (as a > part of the output) > ; For production > web sites, you're strongly encouraged > ; to turn this > feature off, and use error logging instead (see below). > ; Keeping > display_errors enabled on a production web site may reveal > @@ -177,7 +199,7 @@ > > ; PHP's startup sequence are not displayed. It's strongly > > ; recommended to keep display_startup_errors off, except for > > ; when debugging. > -log_errors = Off ; Log errors into a log > file (server-specific log, stderr, or error_log (below)) > +log_errors = On ; Log errors into a log > file (server-specific log, stderr, or error_log (below)) > ; As stated above, > you're strongly advised to use error logging in place of > ; error displaying > on production web sites. > track_errors = Off ; Store the last error/warning > message in $php_errormsg (boolean) > > > > -- > PHP CVS Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-cvs-unsubscribe@lists.php.net > For additional commands, e-mail: php-cvs-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.cvs (#6787) next »