Re: Hiding the source!
| From: | Matt McClanahan | Date: | Thu, 17 Aug 2000 19:58:50 +0000 |
| Subject: | Re: Hiding the source! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12342@lists.php.net to get a copy of this message | ||
On Thu, 17 Aug 2000, Claude Cormier wrote:
> Matt McClanahan wrote:
> >
> > On Thu, 17 Aug 2000, Claude Cormier wrote:
> >
> > > Isn't it a question of permission... if you don't give "r" access
> > > to
> > > others and keep this permission for the owner only... How can a file be
> > > read ?
> >
> > It's an issue of group or global access in many cases. A common
> > requirement of all PHP scripts on a given instance of a web server is that
> > they need to be readable, somehow, by the user that the web server
> > runs as (We assume that the web server is not running as root, since
> > that's a Very Bad(tm) idea).
>
> I am confused here.
>
> Assuming you have a web directory that goes like:
>
> ../www.mydomain.com
> /cgi-bin
> index.html
>
> If the cgi-bin dir has no group permissions and only "x" for public
> users, then what you said above doesn't apply. Right (or worng) ? No
> matter what the PHP source are in cgi-bin, no body can read them.
Ah.. I was operating on the assumption that PHP was an Apache module in
the above scenario. So if you're referring to using PHP as CGI,
pretty much nothing of what I proposed applies. :)
For the record, I typically employ the following directory tree for my
virtualhosts:
/web/www.mydomain.com
/cgi-bin (Only enabled when a site actually needs it)
/php
/templates
(whatever else)
/logs
/webhome
(whatever else)
PHP include path: /web/phpglobal (Optional) and /web/www.mydomain.com/php
Web root: /web/www.mydomain.com/webhome
> > For example, suppose you have five users that write PHP code on your
> > server. Each owns their own script, but the web server user needs access
> > to them all, somehow.
>
> When you say the "web server user needs acess to them all"... you mean
> via the PHP interpreter?
>
> > One common solution is to group-own all the PHP
> > scripts to the group that the web server user is ('websites', for
> > example). However, as a consequence of this setup, all five users
> > have read access to the scripts owned by the other users.
>
> Isn't having each user set up with its one copy of the PHP interprer
> (with "x" only to gorup and public) a better solution ?
>
> Claude
Matt