note 28913 modified in security.hiding by danbrown

From: Date: Tue, 28 Dec 2010 00:46:25 +0000
Subject: note 28913 modified in security.hiding by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-175262@lists.php.net to get a copy of this message
Another way to hide your .php extensions is to use the Apache ForceType directive (which is often referred to as pretty URLs.) Basically you force Apache to parse a file as PHP that matches the trailing directory name in your URL. For example, place this directive in your Apache httpd.conf file: <Location /home> ForceType application/x-httpd-php </Location> and create a php file name "home" in your doc root. This file should not have a .php extension, and can be a php template file. Combined with a function to strip out URL parameters, this can create a new templating system, which can effectively hide your file extensions. In this example, http://www.example.com/home/bar.html would actually use the home script we created, and then the "bar.html" could be used to specify content to include. --was-- Another way to hide your .php extensions is to use the Apache ForceType directive (which is often referred to as pretty URLs.) Basically you force Apache to parse a file as PHP that matches the trailing directory name in your URL. For example, place this directive in your Apache httpd.conf file: <Location /home> ForceType application/x-httpd-php </Location> and create a php file name "home" in your doc root. This file should not have a .php extension, and can be a php template file. Combined with a function to strip out URL parameters, this can create a new templating system, which can effectively hide your file extensions. In this example, http://www.foo.com/home/bar.html would actually use the home script we created, and then the "bar.html" could be used to specify content to include. http://php.net/manual/en/security.hiding.php

« previous php.notes (#175262) next »