Re: Hiding .inc
| From: | Lars Torben Wilson | Date: | Fri, 08 Sep 2000 23:54:52 +0000 |
| Subject: | Re: Hiding .inc | ||
| References: | 1 2 3 4 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15968@lists.php.net to get a copy of this message | ||
Christopher W. Curtis writes:
> Well, you're screwed then because the PHP file doing the include will be
> visible during this time as well, unless you mean to make the security
> for the first file rock-solid and just put anything in the include file,
> kinda like:
>
> index.php:
> <?php Require( "realscript.inc" ); ?>
>
> But maybe I'm just not paranoid enough.
>
> Chris
That's more or less what I would advocate, yes. Never, ever, have
anything sensitive located where it could be revealed to the client.
But then, I also tend to separate PHP and HTML, and I use mostly
reusable code libraries, so there's no real need to have much
scripting in the .html file per se.
--
+----------------------------------------------------------------+
|Torben Wilson <torben@php.net> Netmill iTech|
|http://www.coastnet.com/~torben http://www.netmill.fi|
|Ph: 1 250 383-9735 torben@netmill.fi|
+----------------------------------------------------------------+