Re: Hiding the source!
| From: | Claude Cormier | Date: | Thu, 17 Aug 2000 19:40:29 +0000 |
| Subject: | Re: Hiding the source! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12337@lists.php.net to get a copy of this message | ||
Matt McClanahan wrote:
>
> On Thu, 17 Aug 2000, Claude Cormier wrote:
>
> > Isn't it a question of permission... if you don't give "r" access to
> > others and keep this permission for the owner only... How can a file be
> > read ?
>
> It's an issue of group or global access in many cases. A common
> requirement of all PHP scripts on a given instance of a web server is that
> they need to be readable, somehow, by the user that the web server
> runs as (We assume that the web server is not running as root, since
> that's a Very Bad(tm) idea).
I am confused here.
Assuming you have a web directory that goes like:
../www.mydomain.com
/cgi-bin
index.html
If the cgi-bin dir has no group permissions and only "x" for public
users, then what you said above doesn't apply. Right (or worng) ? No
matter what the PHP source are in cgi-bin, no body can read them.
> For example, suppose you have five users that write PHP code on your
> server. Each owns their own script, but the web server user needs access
> to them all, somehow.
When you say the "web server user needs acess to them all"... you mean
via the PHP interpreter?
> One common solution is to group-own all the PHP
> scripts to the group that the web server user is ('websites', for
> example). However, as a consequence of this setup, all five users
> have read access to the scripts owned by the other users.
Isn't having each user set up with its one copy of the PHP interprer
(with "x" only to gorup and public) a better solution ?
Claude