Re: why the damn phpinfo() is so talkative?

From: Date: Thu, 19 Oct 2000 11:01:14 +0000
Subject: Re: why the damn phpinfo() is so talkative?
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-35513@lists.php.net to get a copy of this message
Max Derkachev wrote: > That's not the case. I did not mean the server where > me myself is a designer, programmer and a sole user. > What if I open an account with a php hosting > provider and call phpinfo() in my own script? PHP is providing access to and listing all environment variables available at the time you run phpinfo(), but not at compile-time. These are the variables you see listed in the section listed "Environment" in phpinfo() output. These are probably more variables than you expect to be there, but they are there in your environment at the time you execute phpinfo(). You may check that with getenv(). It is a well known property of Unix that environment variables inherited from the parent process. If you start httpd from init at system startup, the environment variables are inherited from init, and will subsequently show up within mod_php. If you start httpd manually from a command line, or stop and restart httpd manually from the command line to load a new configuration, the environment variables available in your shell at the time you restart the server will be visible to and inherited by httpd. In both cases you have full control over these variables. Just prune the environment to the desired state immediately before you start httpd. If you are using Apache, suexec and the CGI version of php, additional constraints are enabled: Using the CGI interface will have the webserver create additional environment variables, as this is the primary interface used by CGI to supply parameters to the CGI program. Additionally, suexec does modify and prune the environment seen by the CGI program. Have a look at the suexec source code for details, and modify suexec to suit your needs. In any case this is a problem outside the scope of PHP, as this environment is shared by and visible to all CGI programs and all Apache modules. Just control your server environment to contains only nonsensitive information. Kristian -- Kristian Köhntopp, NetUSE AG Siemenswall, D-24107 Kiel Tel: +49 431 386 436 00, Fax: +49 431 386 435 99 Using PHP3? See our web development library at http://phplib.netuse.de/

« previous php.dev (#35513) next »