note 26943 added to function.highlight-file
| From: | koffieboer at belgacom dot net | Date: | Mon, 18 Nov 2002 16:46:09 +0000 |
| Subject: | note 26943 added to function.highlight-file | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-39644@lists.php.net to get a copy of this message | ||
@ b underslash h at utanet dot at:
I would actually do it the other way around, make an array with files that CAN be viewed, then you
are sure that you can't have any accidents... And if you are working on a (badly configured)
virtual host, they could actually view someone else's site code - who is maybe (and even
probably) not served by this, and you could probably view their passwords. Another remark - never
store passwords inside my web tree - otherwise, if the phpmodule goes down, or smth goes wrong with
apache, showing the php source instead of the interpreted page - you have the same problem anyway.
This happens sometimes (most of the times user/admin error - but it happens) and when this happens,
you have a problem. (I actually got a fried's database password and backdoor site admin pwd
this way - he was lucky I am such a nice person and gave him some tips and advice on security ;) :P)
Actually - I would never ever give a filename as a GET or POST parameter in my life, give it a
"code" or a number, but not a filename.
Do it like this:
$ACCEPT_HIGHLIGHT['file1'] = '../some/file.php';
$ACCEPT_HIGHLIGHT['file2'] = '../someother/file.php';
// Add more here...
function my_highlight_file($file)
{
GLOBAL $ACCEPT_HIGHLIGHT;
$filename = $ACCEPT_HIGHLIGHT[$file];
if (!isSet( $filename)) echo "File not found";
else {
/* do your highlight stuff */
highlight_file($filename);
}
}
my_highlight_file($_GET['highlight']);
in this case, when you access the page with "http://mydomain.com/showfile.php?highlight=file1"
it will display the correct file.
When you would access it with "http://mydomain.com/showfile.php?highlight=unknownfle"
then it would display "File not found" instead.
Note that the above code was just invented on the moment of posting this - it is never ever tested
by me - but it should work (I use simular things frequently)
--
http://www.php.net/manual/en/function.highlight-file.php
http://master.php.net/manage/user-notes.php?action=edit+26943
http://master.php.net/manage/user-notes.php?action=delete+26943
http://master.php.net/manage/user-notes.php?action=reject+26943