Re: .inc or .anything - better or worse ?
| From: | Matthew Ballard | Date: | Wed, 06 Dec 2000 09:56:07 +0000 |
| Subject: | Re: .inc or .anything - better or worse ? | ||
| References: | 1 2 3 4 5 6 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-28866@lists.php.net to get a copy of this message | ||
As far as I can tell, using .inc is more for convenience of naming than anything else. I write my include files so they can't stand on their own, so I know not to try to use a .inc file as anything other than an include, and so I can quickly pull a list of them with ls *inc . If you're worried about security as far as viewing (if people can even figure out the names you use for them in the first place), then either keep them out of the webroot, or put them in a .htaccess protected directory set to deny all, or add:
<Files ~ "\.inc$">
Order allow,deny
Deny from all
</Files>
to the httpd.conf (might work from .htaccess to, but I don't know) file, so it will deny access to inc files (assuming you are using Apache).
As far as setting all html files to go through PHP, if there is only one or two html files being used anyway, then the load would be neglible, but it depends on server load.
Matthew
At 10:29 AM 12/6/2000 +1100, you wrote:
At 09:59 AM 28/11/2000, you wrote:Most people add .inc to their PHP parser - AFAIK this is kind of a standard practice. A person looking at main.inc would get "Document Contained No Data". Not a huge security risk IMO - of course mine are outside of the docroot ;O)Is there any specific why it an unwritten law that included files are .inc ? The first ever tutorial I did for PHP actually made included files .php and the reason it said this was because some places may not protect .inc (or other extentions) and also may not allow you access to go back a directory and use that area. Ive been using .php for all my included files (mostly all my functions are in these files) and never had a problem but it seems that most people use .inc instead.