Re: Hiding the source!

From: Date: Thu, 17 Aug 2000 19:58:50 +0000
Subject: Re: Hiding the source!
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-12342@lists.php.net to get a copy of this message
On Thu, 17 Aug 2000, Claude Cormier wrote: > Matt McClanahan wrote: > > > > On Thu, 17 Aug 2000, Claude Cormier wrote: > > > > > Isn't it a question of permission... if you don't give "r" access > > > to > > > others and keep this permission for the owner only... How can a file be > > > read ? > > > > It's an issue of group or global access in many cases. A common > > requirement of all PHP scripts on a given instance of a web server is that > > they need to be readable, somehow, by the user that the web server > > runs as (We assume that the web server is not running as root, since > > that's a Very Bad(tm) idea). > > I am confused here. > > Assuming you have a web directory that goes like: > > ../www.mydomain.com > /cgi-bin > index.html > > If the cgi-bin dir has no group permissions and only "x" for public > users, then what you said above doesn't apply. Right (or worng) ? No > matter what the PHP source are in cgi-bin, no body can read them. Ah.. I was operating on the assumption that PHP was an Apache module in the above scenario. So if you're referring to using PHP as CGI, pretty much nothing of what I proposed applies. :) For the record, I typically employ the following directory tree for my virtualhosts: /web/www.mydomain.com /cgi-bin (Only enabled when a site actually needs it) /php /templates (whatever else) /logs /webhome (whatever else) PHP include path: /web/phpglobal (Optional) and /web/www.mydomain.com/php Web root: /web/www.mydomain.com/webhome > > For example, suppose you have five users that write PHP code on your > > server. Each owns their own script, but the web server user needs access > > to them all, somehow. > > When you say the "web server user needs acess to them all"... you mean > via the PHP interpreter? > > > One common solution is to group-own all the PHP > > scripts to the group that the web server user is ('websites', for > > example). However, as a consequence of this setup, all five users > > have read access to the scripts owned by the other users. > > Isn't having each user set up with its one copy of the PHP interprer > (with "x" only to gorup and public) a better solution ? > > Claude Matt

« previous php.general (#12342) next »