Re: Allowing [SAPI=] entries in ini files.

From: Date: Wed, 20 Nov 2013 10:22:08 +0000
Subject: Re: Allowing [SAPI=] entries in ini files.
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-70223@lists.php.net to get a copy of this message
On Wed, Nov 20, 2013 at 11:06 AM, Sebastian Krebs <krebs.seb@gmail.com> wrote: > 2013/11/20 Michael Wallner <mike@php.net> > >> On 19 November 2013 19:51, Sebastian Krebs <krebs.seb@gmail.com> wrote: >> >> > Just my 2 cents, but that sounds more like an issue with your >> > provider/hoster and not with PHP. I always thought of the additional >> > php.ini as a way to change some details and not a way to set up the whole >> > runtime. Especially when a user has write access to that file it seems to >> > me also an security issue, when PHP allows to set/change critical >> settings >> > there. >> >> You totally miss the point, Sebastian. As Richard already explained in >> his example, he as access to the ini-scan-dir, so he could set >> whatever setting he wants, just not SAPI-specific, but for all SAPIs. >> > > OK, but that doesn't change my opinion, that this in the hosters > responsibility, what he provides and what not. INI sections allow one to customize directories settings and having this feature to do some other settings based on the SAPI looks like a good complement. Obviously shared hosted applications are not the target for such features as they usually do not have access to php.ini but .htacess or .user.ini only. Cheers, -- Pierre @pierrejoye | http://www.libgd.org

« previous php.internals (#70223) next »