Bug #14071: 'admin-values' php.ini also for CGI-binary

From: Date: Thu, 15 Nov 2001 18:12:06 +0000
Subject: Bug #14071: 'admin-values' php.ini also for CGI-binary
Groups: php.dev 
Request: Send a blank email to php-dev+get-70584@lists.php.net to get a copy of this message
From:             maddog2k@maddog2k.nl
Operating system: Linux/FreeBSD
PHP version:      4.0.6
PHP Bug Type:     Feature/Change Request
Bug description:  'admin-values' php.ini also for CGI-binary

The problem I ran into while using PHP as CGI-binary under for example
Apache instead of mod_php, is that you can't simply allow restrictive
overrides of certain values.

If you for example put a 'php.ini' file in a directory, PHP will read that
file...completely ignoring the /usr/local/lib/php.ini

Let's say we have a malicious user who wants to upload files of 100MB, he
could simply do that by allowing this in his 'own' php.ini (post_max_size).
I don't think this is a wanted situation.

The restriction I'm using now (thanks to Mathieu), is by an edited
php_ini.c that reads only the php.ini from PHP_CONFIG_FILE_PATH. 

Why not using the same guidelines as with the ini_set() function ? Or an
option in the 'default' .ini, to turn this behaviour on...:))
-- 
Edit bug report at: http://bugs.php.net/?id=14071&edit=1



Thread (1 message)

  • maddog2k at maddog2k dot nl
« previous php.dev (#70584) next »