Re: PHP6, drop open_basedir?

From: Date: Tue, 17 Jun 2014 09:15:35 +0000
Subject: Re: PHP6, drop open_basedir?
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-74935@lists.php.net to get a copy of this message
On Tue, Jun 17, 2014 at 10:26 AM, Pierre Joye <pierre.php@gmail.com> wrote: > hi, > > One of the last reminding so called "security" feature is open_basedir. > > On Windows f.e. it is very easy to create application pool with the > right users/permissions settings (IIS) or only permissions settings > (Apache). It is not possible to create one user per host on Apache > using mod_php but I think it is acceptable as it is mostly used as > development server or dedicated apps. > > On linux, fcgi/fpm with linux permissions systems allow pretty much > the same. And my solutions exist for a per user/application isolation > system. > > I think it is not worth the effort to keep maintaining something that > will never be as safe as system level permissions. > > What do you think about removing it in php 6? Thoughts? I'am obviously +1. This param is not needed any more, it's been very easy to abuse it and it's removal will lead to many places of code cleaning :-) Julien

« previous php.internals (#74935) next »