Bug #864: Query string overrides apache envars
| From: | explorer at flame dot org | Date: | Wed, 21 Oct 1998 18:18:29 +0000 |
| Subject: | Bug #864: Query string overrides apache envars | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-1941@lists.php.net to get a copy of this message | ||
From: explorer@flame.org
Operating system: NetBSD/i386-1.3.2+
PHP version: 3.0 Latest CVS (21/10/1998)
PHP Bug Type: Other
Bug description: Query string overrides apache envars
When using Basic auth, Apache sets envar(REMOTE_USER) to the name
authenticated to. However, using a query like
http://foo.com/path/?REMOTE_USER=foo
will cause the initial value of $REMOTE_USER to be changed to foo in
the php script.
It seems to me that Apache vars should be read-only. That is, read only while in the query string
parsing code. I should be able to set these in php scripts, if I wanted to, but I shouldn't be
able to override ($HOME for instance) these.
Your documentation says that envars become php3 vars. Mention that these can be trivially
overwritten should at the least be mentioned there, if this (imho) bug isn't fixed.
--Michael
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net