Re: Keeping "Secrets" in PHP Files
| From: | Garth Dahlstrom | Date: | Sat, 29 Jun 2002 02:10:05 +0000 |
| Subject: | Re: Keeping "Secrets" in PHP Files | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-104459@lists.php.net to get a copy of this message | ||
here's an idea, perhaps something like this
can be used...
You set a decryptionkey value in your vhost
(I don't know if you can do this with php_value
or perhaps an apache directive)
<VirtualHost 123.123.123.123>
ServerName www.example.com
DocumentRoot /home/example/htdocs
php_value decryptionkey "123456789"
</VirtualHost>
encode your secret data using the decryptionkey
before hand, and then decode it on the fly using
the environment variable present in only in your
vhost.
I'm hoping that no one outside of your vhost can
see the value of that variable. (does anyone know
if you can pull environment variables from other
vhosts or if PHP can read httpd.conf?)
-Garth
Northern.CA ===--
http://www.northern.ca
Canada's Search Engine