Re: Why PHP may further to break authorization?
| From: | Yury Bokhoncovich | Date: | Tue, 12 Sep 2000 06:44:20 +0000 |
| Subject: | Re: Why PHP may further to break authorization? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-33003@lists.php.net to get a copy of this message | ||
Hi!
Rasmus Lerdorf wrote:
>
> > Synopsys: both PHP3 and PHP4 further that any user even w/o required
> > credentials
> > can get info protected by .htaccess file.
> >
> > Details: IF I have a directory protected by .htacces file, and I give a
> > full name of any
> > script-file in this directory, I'll get output of this script instead of
> > 401 Error Message,
> > which I'm expecting to get.:(
>
> Then your Apache config is completely messed up. Apache does the access
> check long before it calls the content handling hook (which is where PHP
> gets called), so if there is a bug it could not possibly be in PHP.
>
Well, but why my Apache is working fine if I have compiled it w/o PHP at
all?
I.e. I eager to say that the issue disappears if Apache was compiled
with the same options but PHP engine.
> You need to read up on Apache auth stuff. You are using a <LIMIT GET
Yep. Moving "require" directive out of LIMIT block has solved the issue.
> POST> block. All I have to do to get around this is send you a PUT
> request.
Didn't catch you exactly, did you mean that another method (PUT and so
on) is working anyway?
--
WBR, Yury Bokhoncovich,
SysAdmin at FIS.
voice call: +7 (3832) 119727 pager: +7 (3832) 186555/61621
mailto: byg@fis.ru visit us: http://www.fis.ru/
Unix is like a wigwam -- no Gates, no Windows, and an Apache inside.