note 28980 added to security.hiding
| From: | php-general at lists dot php dot net | Date: | Wed, 29 Jan 2003 16:53:50 +0000 |
| Subject: | note 28980 added to security.hiding | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-43081@lists.php.net to get a copy of this message | ||
PS. If you want to use pretty URLs (i.e. hide your .php extensions) AND you have safe-mode=on, the
previous example (ForceType) won't work for you. The problem is that safe-mode forces Apache
to honor trailing characters in a requested URL. This means that:
http://www.foo.com/home
would still be processed by the home script in our doc root, but for:
http://www.foo.com/home/contact_us.html
apache would actually look for the /home/contact_us.html file in our doc root.
The best solution I've found is to set up a virtual host (which I do for everything, even the
default doc root) and override the trailing characters handling within the virtual host. So, for a
virtual host listening on port 8080, the apache directives would look like this:
<VirtualHost *:8080>
DocumentRoot /web/doc_root
Alias /home "/web/doc_root/home.php"
AcceptPathInfo On
</VirtualHost>
Some people might question why we are overriding the trailing characters handling (with the
AcceptPathInfo directive) instead of just turning safe-mode=off. The reason is that safe mode sets
global limitations on the entire server, which can then be turned on or left off for each specific
virtual host. This is the equivilent of blocking all connections on a firewall, and then opening up
only the ones you want, which is a lot safer than leaving everything open globally, and assuming
your programmers will never overlook a possible security hole.
--
http://www.php.net/manual/en/security.hiding.php
http://master.php.net/manage/user-notes.php?action=edit+28980
http://master.php.net/manage/user-notes.php?action=delete+28980
http://master.php.net/manage/user-notes.php?action=reject+28980