Re: cvs: php4 / php.ini-recommended
| From: | derick@php.net | Date: | Fri, 01 Mar 2002 06:32:40 +0000 |
| Subject: | Re: cvs: php4 / php.ini-recommended | ||
| References: | 1 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-9524@lists.php.net to get a copy of this message | ||
Hello Shane,
On Fri, 1 Mar 2002, Shane Caraveo wrote:
> shane Thu Feb 28 21:10:00 2002 EDT
>
> Modified files:
> /php4 php.ini-recommended
> Log:
> document force-redirect in php.ini
Are you going to change php.ini-dist too?
Derick
>
>
> Index: php4/php.ini-recommended
> diff -u php4/php.ini-recommended:1.65 php4/php.ini-recommended:1.66
> --- php4/php.ini-recommended:1.65 Fri Feb 8 16:19:54 2002
> +++ php4/php.ini-recommended Thu Feb 28 21:09:59 2002
> @@ -365,6 +365,10 @@
> ;include_path = ".;c:\php\includes"
>
> ; The root of the PHP pages, used only if nonempty.
> +; if PHP was not compiled with FORCE_REDIRECT, you SHOULD set doc_root
> +; if you are running php as a CGI under any web server (other than IIS)
> +; see documentation for security issues. The alternate is to use the
> +; cgi.force_redirect configuration below
> doc_root =
>
> ; The directory under which PHP opens the script using /~usernamem used only
> @@ -378,6 +382,19 @@
> ; properly in multithreaded servers, such as IIS or Zeus, and is automatically
> ; disabled on them.
> enable_dl = On
> +
> +; cgi.force_redirect is necessary to provide security running PHP as a CGI under
> +; most web servers. Left undefined, PHP turns this on by default. You can
> +; turn it off here AT YOUR OWN RISK
> +; **You CAN safely turn this off for IIS, in fact, you MUST.**
> +; cgi.force_redirect = 1
> +
> +; if cgi.force_redirect is turned on, and you are not running under Apache or Netscape
> +; (iPlanet) web servers, you MAY need to set an environment variable name that PHP
> +; will look for to know it is OK to continue execution. Setting this variable MAY
> +; cause security issues, KNOW WHAT YOU ARE DOING FIRST.
> +; cgi.redirect_status_env = ;
> +
>
>
> ;;;;;;;;;;;;;;;;
>
>
>
> --
> PHP CVS Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>