cvs: php4 / php.ini-recommended
| From: | Shane Caraveo | Date: | Fri, 01 Mar 2002 02:10:00 +0000 |
| Subject: | cvs: php4 / php.ini-recommended | ||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-9520@lists.php.net to get a copy of this message | ||
shane Thu Feb 28 21:10:00 2002 EDT
Modified files:
/php4 php.ini-recommended
Log:
document force-redirect in php.ini
Index: php4/php.ini-recommended
diff -u php4/php.ini-recommended:1.65 php4/php.ini-recommended:1.66
--- php4/php.ini-recommended:1.65 Fri Feb 8 16:19:54 2002
+++ php4/php.ini-recommended Thu Feb 28 21:09:59 2002
@@ -365,6 +365,10 @@
;include_path = ".;c:\php\includes"
; The root of the PHP pages, used only if nonempty.
+; if PHP was not compiled with FORCE_REDIRECT, you SHOULD set doc_root
+; if you are running php as a CGI under any web server (other than IIS)
+; see documentation for security issues. The alternate is to use the
+; cgi.force_redirect configuration below
doc_root =
; The directory under which PHP opens the script using /~usernamem used only
@@ -378,6 +382,19 @@
; properly in multithreaded servers, such as IIS or Zeus, and is automatically
; disabled on them.
enable_dl = On
+
+; cgi.force_redirect is necessary to provide security running PHP as a CGI under
+; most web servers. Left undefined, PHP turns this on by default. You can
+; turn it off here AT YOUR OWN RISK
+; **You CAN safely turn this off for IIS, in fact, you MUST.**
+; cgi.force_redirect = 1
+
+; if cgi.force_redirect is turned on, and you are not running under Apache or Netscape
+; (iPlanet) web servers, you MAY need to set an environment variable name that PHP
+; will look for to know it is OK to continue execution. Setting this variable MAY
+; cause security issues, KNOW WHAT YOU ARE DOING FIRST.
+; cgi.redirect_status_env = ;
+
;;;;;;;;;;;;;;;;