cvs: php4 / php.ini-recommended

From: Date: Fri, 01 Mar 2002 02:10:00 +0000
Subject: cvs: php4 / php.ini-recommended
Groups: php.cvs 
Request: Send a blank email to php-cvs+get-9520@lists.php.net to get a copy of this message
shane Thu Feb 28 21:10:00 2002 EDT Modified files: /php4 php.ini-recommended Log: document force-redirect in php.ini Index: php4/php.ini-recommended diff -u php4/php.ini-recommended:1.65 php4/php.ini-recommended:1.66 --- php4/php.ini-recommended:1.65 Fri Feb 8 16:19:54 2002 +++ php4/php.ini-recommended Thu Feb 28 21:09:59 2002 @@ -365,6 +365,10 @@ ;include_path = ".;c:\php\includes" ; The root of the PHP pages, used only if nonempty. +; if PHP was not compiled with FORCE_REDIRECT, you SHOULD set doc_root +; if you are running php as a CGI under any web server (other than IIS) +; see documentation for security issues. The alternate is to use the +; cgi.force_redirect configuration below doc_root = ; The directory under which PHP opens the script using /~usernamem used only @@ -378,6 +382,19 @@ ; properly in multithreaded servers, such as IIS or Zeus, and is automatically ; disabled on them. enable_dl = On + +; cgi.force_redirect is necessary to provide security running PHP as a CGI under +; most web servers. Left undefined, PHP turns this on by default. You can +; turn it off here AT YOUR OWN RISK +; **You CAN safely turn this off for IIS, in fact, you MUST.** +; cgi.force_redirect = 1 + +; if cgi.force_redirect is turned on, and you are not running under Apache or Netscape +; (iPlanet) web servers, you MAY need to set an environment variable name that PHP +; will look for to know it is OK to continue execution. Setting this variable MAY +; cause security issues, KNOW WHAT YOU ARE DOING FIRST. +; cgi.redirect_status_env = ; + ;;;;;;;;;;;;;;;;

« previous php.cvs (#9520) next »