note 26943 added to function.highlight-file

From: Date: Mon, 18 Nov 2002 16:46:09 +0000
Subject: note 26943 added to function.highlight-file
Groups: php.notes 
Request: Send a blank email to php-notes+get-39644@lists.php.net to get a copy of this message
@ b underslash h at utanet dot at: I would actually do it the other way around, make an array with files that CAN be viewed, then you are sure that you can't have any accidents... And if you are working on a (badly configured) virtual host, they could actually view someone else's site code - who is maybe (and even probably) not served by this, and you could probably view their passwords. Another remark - never store passwords inside my web tree - otherwise, if the phpmodule goes down, or smth goes wrong with apache, showing the php source instead of the interpreted page - you have the same problem anyway. This happens sometimes (most of the times user/admin error - but it happens) and when this happens, you have a problem. (I actually got a fried's database password and backdoor site admin pwd this way - he was lucky I am such a nice person and gave him some tips and advice on security ;) :P) Actually - I would never ever give a filename as a GET or POST parameter in my life, give it a "code" or a number, but not a filename. Do it like this: $ACCEPT_HIGHLIGHT['file1'] = '../some/file.php'; $ACCEPT_HIGHLIGHT['file2'] = '../someother/file.php'; // Add more here... function my_highlight_file($file) { GLOBAL $ACCEPT_HIGHLIGHT; $filename = $ACCEPT_HIGHLIGHT[$file]; if (!isSet( $filename)) echo "File not found"; else { /* do your highlight stuff */ highlight_file($filename); } } my_highlight_file($_GET['highlight']); in this case, when you access the page with "http://mydomain.com/showfile.php?highlight=file1" it will display the correct file. When you would access it with "http://mydomain.com/showfile.php?highlight=unknownfle" then it would display "File not found" instead. Note that the above code was just invented on the moment of posting this - it is never ever tested by me - but it should work (I use simular things frequently) -- http://www.php.net/manual/en/function.highlight-file.php http://master.php.net/manage/user-notes.php?action=edit+26943 http://master.php.net/manage/user-notes.php?action=delete+26943 http://master.php.net/manage/user-notes.php?action=reject+26943

« previous php.notes (#39644) next »