note 28913 added to security.hiding
| From: | Azureash at rack1 dot php dot net | Date: | Mon, 27 Jan 2003 22:34:03 +0000 |
| Subject: | note 28913 added to security.hiding | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-42888@lists.php.net to get a copy of this message | ||
Another way to hide your .php extensions is to use the Apache ForceType directive (which is often
referred to as pretty URLs.) Basically you force Apache to parse a file as PHP that matches the
trailing directory name in your URL.
For example, place this directive in your Apache httpd.conf file:
<Location /home>
ForceType application/x-httpd-php
</Location>
and create a php file name "home" in your doc root. This file should not have a .php
extension, and can be a php template file. Combined with a function to strip out URL parameters,
this can create a new templating system, which can effectively hide your file extensions.
In this example,
http://www.foo.com/home/bar.html
would actually use the home script we created, and then the "bar.html" could be used to
specify content to include.
--
http://www.php.net/manual/en/security.hiding.php
http://master.php.net/manage/user-notes.php?action=edit+28913
http://master.php.net/manage/user-notes.php?action=delete+28913
http://master.php.net/manage/user-notes.php?action=reject+28913