Re: Re: [PHP] can it be done? <security>
| From: | Rasmus Lerdorf | Date: | Tue, 01 Aug 2000 22:16:42 +0000 |
| Subject: | Re: Re: [PHP] can it be done? <security> | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-9581@lists.php.net to get a copy of this message | ||
> >I am a on webhost, I have 3 dirs, public_html,
> >public_ftp, and mymailbox. To put my include file
> >outside of the tree would I create a dir in my
> >home dir? If so to what extent of permissions
> >should be set?
>
> Anything under your main HTML directory (typically
> htdocs or public_html) is viable. Put it in, or under, your
> cgi-bin, directory or under your account's root directory.
> It only need read permission.
I tend to just name all my include files *.inc and then add a
LocationMatch rule to my httpd.conf to deny direct access to those
files. That way I don't have files scattered all over the place.
eg.
<LocationMatch "^/[^/]*.inc">
Order allow,deny
Deny from all
</LocationMatch>
This denies access to *.inc in the DOCUMENT_ROOT directory, but not below
that.
-Rasmus