Re: [PHP4BETA] You should not have to choose

From: Date: Sun, 21 Nov 1999 07:44:01 +0000
Subject: Re: [PHP4BETA] You should not have to choose
References: 1  Groups: php.dev php.version4 
Request: Send a blank email to php-dev+get-12840@lists.php.net to get a copy of this message
JJ>> But it's not possible to: JJ>> 1) Send headers like HTTP 401, because Apache will add Content-type: JJ>> text/html before your HTTP-header. It's possible to define own headers. If you do not want Apache headers at all, you can run PHP as nph-script and make all headers by yourself. JJ>> 2) Use PHP-scripts that uses the variable $SCRIPT_NAME. Well, so do not use incompatible variables. JJ>> 3) Achieve the same performence as when using the mod_php version. Well, it isn't also possible to go with Volkswagen beetle made in 50th as if you were driving Porshe... CGI is a performance hit, you can do nothing about it. Maybe FastCGI could be a bit of help - I do not know what happened to FastCGI support since PHP/FI... JJ>> I think it would be a very good idea if you could suEXEC php-scripts JJ>> even if you use the module version of PHP. That would require or full integration of suEXEC into PHP, or running httpd as root (which is Bad Thing (TM)). Since mod_php will be still running as Apache user (being integral part of httpd executable), it means that you still will have to run external suid binary - so here goes well-known well-debugged suexec program. I do not see a way to do this without calling external program, with present UNIX security model. One thing that could be solution is having some PHP-executing daemon, running as root and switching to a user ID, executing script for him and returning results (something along the lines qmail and other MDAs work). But this almost makes it another small httpd. I am in doubt if it worth the trouble. -- Stanislav Malyshev Zend Technologies Ltd. stas@zend.com http://www.zend.com/ 050-624945

« previous php.dev (#12840) next »