RE: [PHP] "blackboxing" my global functions
| From: | David Robley | Date: | Tue, 24 Oct 2000 00:51:14 +0000 |
| Subject: | RE: [PHP] "blackboxing" my global functions | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-21835@lists.php.net to get a copy of this message | ||
> -----Original Message-----
> From: Lawrence.Sheed@dfait-maeci.gc.ca
> [mailto:Lawrence.Sheed@dfait-maeci.gc.ca]
> Sent: Monday, October 23, 2000 04:16
> To: mstearne@entermix.com; huntsman@hermes.nisu.flinders.edu.au
> Cc: theoj@transport.com; php-general@lists.php.net
> Subject: RE: [PHP] "blackboxing" my global functions
>
>
> It won't work though.
>
> If the files are accessible by Apache (and php by because apache runs it)
> then they can just do a file open, read into a string and print.
>
> eg:
>
> $filename = "your_secret_file_here.php";
>
> $fd = fopen( $filename, "r" );
> $contents = fread( $fd, filesize( $filename ) );
> fclose( $fd );
> print ($contents);
>
> -----Original Message-----
> From: Michael Stearne [mailto:mstearne@entermix.com]
> Sent: October 23, 2000 11:13 AM
> To: David Robley
> Cc: Theodore Jones; PHP General List
> Subject: Re: [PHP] "blackboxing" my global functions
>
>
> That is a good idea.
>
> David Robley wrote:
>
> > On Mon, 23 Oct 2000, Theodore Jones wrote:
> > > Hello,
> > >
> > > I act as my own full-service hosting and design company and I use PHP in
> > > some of my site designs.
> > >
> > > I have spent considerable time on some of my functions and such which I
> > > generally like to put into an include file which can be accessed by all
> > > pages "globally" within the site. What I am wondering is, how can I
> > > "black-box" this global function include file such that it is protected
> > > from the site "owners" FTP'ing in and downloading/viewing, but is
> > > still
> > > accessible through the HTTP interactions to pump out HTML to the
> > > browser?
> > >
> > > In a sense I consider the PHP programming I have done my "investment"
> > > and "property" and not a part of the design of the site sold to the
> > > client, so I seek to protect my investment and keep them from just
> > > running off with my code and hosting on a different server.
> > >
> > > If anyone has any ideas (perhaps I'm missing something obvious as a
> > > solution), please advise.
> > >
> > > Thanks in Advance,
> > >
> > > ~ Theo
> >
> > Put your include files in a directory that is not under the web root, and
> > that can't be accessed via ftp except by the good guys.
> >
OK - after a night's rest I would add: Use the auto_prepend configuration
directive, in httpd.conf, to prepend a file that calls, or includes, the
stuff you want kept confidential.
--
David Robley | WEBMASTER & Mail List Admin
RESEARCH CENTRE FOR INJURY STUDIES | http://www.nisu.flinders.edu.au/
AusEinet | http://auseinet.flinders.edu.au/
Flinders University, ADELAIDE, SOUTH AUSTRALIA