Re: cvs: php4 / php.ini-recommended

From: Date: Fri, 01 Mar 2002 06:32:40 +0000
Subject: Re: cvs: php4 / php.ini-recommended
References: 1  Groups: php.cvs 
Request: Send a blank email to php-cvs+get-9524@lists.php.net to get a copy of this message
Hello Shane, On Fri, 1 Mar 2002, Shane Caraveo wrote: > shane Thu Feb 28 21:10:00 2002 EDT > > Modified files: > /php4 php.ini-recommended > Log: > document force-redirect in php.ini Are you going to change php.ini-dist too? Derick > > > Index: php4/php.ini-recommended > diff -u php4/php.ini-recommended:1.65 php4/php.ini-recommended:1.66 > --- php4/php.ini-recommended:1.65 Fri Feb 8 16:19:54 2002 > +++ php4/php.ini-recommended Thu Feb 28 21:09:59 2002 > @@ -365,6 +365,10 @@ > ;include_path = ".;c:\php\includes" > > ; The root of the PHP pages, used only if nonempty. > +; if PHP was not compiled with FORCE_REDIRECT, you SHOULD set doc_root > +; if you are running php as a CGI under any web server (other than IIS) > +; see documentation for security issues. The alternate is to use the > +; cgi.force_redirect configuration below > doc_root = > > ; The directory under which PHP opens the script using /~usernamem used only > @@ -378,6 +382,19 @@ > ; properly in multithreaded servers, such as IIS or Zeus, and is automatically > ; disabled on them. > enable_dl = On > + > +; cgi.force_redirect is necessary to provide security running PHP as a CGI under > +; most web servers. Left undefined, PHP turns this on by default. You can > +; turn it off here AT YOUR OWN RISK > +; **You CAN safely turn this off for IIS, in fact, you MUST.** > +; cgi.force_redirect = 1 > + > +; if cgi.force_redirect is turned on, and you are not running under Apache or Netscape > +; (iPlanet) web servers, you MAY need to set an environment variable name that PHP > +; will look for to know it is OK to continue execution. Setting this variable MAY > +; cause security issues, KNOW WHAT YOU ARE DOING FIRST. > +; cgi.redirect_status_env = ; > + > > > ;;;;;;;;;;;;;;;; > > > > -- > PHP CVS Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php >

« previous php.cvs (#9524) next »