RE: [PHP] Hiding the source!
| From: | Matt McClanahan | Date: | Thu, 17 Aug 2000 17:29:19 +0000 |
| Subject: | RE: [PHP] Hiding the source! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12302@lists.php.net to get a copy of this message | ||
On Thu, 17 Aug 2000, Tyler Longren wrote:
> Yup...I suppose so. I did not think of that. :)
>
> On Thu, 17 Aug 2000, James Atkinson wrote:
> > Date: Thu, 17 Aug 2000 10:23:11 -0700
> > To: PHP <php-general@lists.php.net>
> > From: James Atkinson <james.atkinson@ebox.ca>
> > Subject: RE: [PHP] Hiding the source!
> >
> > It depends, if all your include files end in .inc, and you don't parse
> > ..inc's though the PHP parser. Then someone types in
> > http://www.yourdomain.com/includes/db_login.inc they get
> > your database
> > login and password...and whatever else. So that brings up another point
> > that you should name your include files so they are parsed though the
> > parser. :)
I would also submit that if you're developing applications on a PHP server
where you aren't in control of the web server, be wary. :) Even if the
web server were parsing .inc files properly, I wouldn't assume that it
would always be that way. All it takes is one line change to break that,
and it may even happen accidentally.
For my part, I keep all remotely important PHP code outside of the web
tree, and just include/require the functions I need.
Matt