Re: Looking for an informed opinion
| From: | Andrian Pervazov | Date: | Wed, 29 Nov 2000 01:55:28 +0000 |
| Subject: | Re: Looking for an informed opinion | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-27746@lists.php.net to get a copy of this message | ||
You can setup Apache (if that's the server you're using) to deny access
to inc files if requested directly from a browser. This will still allow
you to include them in php or html files which is their purpose anyway
<Files *.inc>
AllowOverride AuthConfig FileInfo Indexes Limit Options
Order allow,deny
Deny from all
</Files>
Andrian
lee@server.mediawaveonline.com wrote:
>
> Accually Ive setup in httpd.conf for apache that apache should consider
> all .inc files as .php files. If someone typed my inc file in the url bar
> apache would try to parse it... because I almost allways only put
> functions in my include files, and never output anything to the screen,
> parsing it would do nothing.
>
> But you do have a good point, people do have to take this into
> consideration when setting up their httpd.conf file.
>
> Chris Lee
> Mediawaveonline.com
>
> On Tue, 28 Nov 2000, Robert B. Easter wrote:
>
> > On Monday 27 November 2000 21:31, Chris Lee wrote:
> > > This is a big personal opinion about programming, everyone is different,
> > > but I also like to keep my php code less than 1000 lines. The total code
> > > executed may be much more because of included files. I personally find it
> > > hard to keep track of more then 1000 lines at a time, if I split it up
> > > its alot easier. Just try and break up your code logically, don't have
> > > one include that does everything, I like to try an only put function's in
> > > include (not allways, but most often)
> > >
> > > include_once("$DOCUMENT_ROOT/include/session.inc");
> > > include_once("$DOCUMENT_ROOT/include/database.inc");
> > > include_once("$DOCUMENT_ROOT/include/time_date.inc");
> >
> > I notice your *.inc files are possibly accessible via the web since they are
> > under $DOCUMENT_ROOT. People can see how you coded them. Maybe you don't
> > care. If you do care, then you'll want to have it go back one directory or
> > to some other directory that is outside $DOCUMENT_ROOT where the webserver
> > can't serve them out in plain view.
> >
> >
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net