cvs: php4 / php.ini-dist

From: Date: Fri, 01 Mar 2002 06:48:28 +0000
Subject: cvs: php4 / php.ini-dist
Groups: php.cvs 
Request: Send a blank email to php-cvs+get-9528@lists.php.net to get a copy of this message
shane Fri Mar 1 01:48:28 2002 EDT Modified files: /php4 php.ini-dist Log: add stuff here also. Index: php4/php.ini-dist diff -u php4/php.ini-dist:1.111 php4/php.ini-dist:1.112 --- php4/php.ini-dist:1.111 Wed Feb 27 18:50:41 2002 +++ php4/php.ini-dist Fri Mar 1 01:48:27 2002 @@ -360,6 +360,10 @@ ;include_path = ".;c:\php\includes" ; The root of the PHP pages, used only if nonempty. +; if PHP was not compiled with FORCE_REDIRECT, you SHOULD set doc_root +; if you are running php as a CGI under any web server (other than IIS) +; see documentation for security issues. The alternate is to use the +; cgi.force_redirect configuration below doc_root = ; The directory under which PHP opens the script using /~usernamem used only @@ -374,6 +378,17 @@ ; disabled on them. enable_dl = On +; cgi.force_redirect is necessary to provide security running PHP as a CGI under +; most web servers. Left undefined, PHP turns this on by default. You can +; turn it off here AT YOUR OWN RISK +; **You CAN safely turn this off for IIS, in fact, you MUST.** +; cgi.force_redirect = 1 + +; if cgi.force_redirect is turned on, and you are not running under Apache or Netscape +; (iPlanet) web servers, you MAY need to set an environment variable name that PHP +; will look for to know it is OK to continue execution. Setting this variable MAY +; cause security issues, KNOW WHAT YOU ARE DOING FIRST. +; cgi.redirect_status_env = ; ;;;;;;;;;;;;;;;; ; File Uploads ;

« previous php.cvs (#9528) next »