note 35182 deleted from function.file-exists by sniper
| From: | sniper@php.net | Date: | Sun, 23 Nov 2003 01:27:04 +0000 |
| Subject: | note 35182 deleted from function.file-exists by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-60834@lists.php.net to get a copy of this message | ||
Note Submitter: andy@acomm-hosting.co.uk
----
PHP 4.3.2 on Apache 1.3.27 has some interesting effects. On all VHOSTS we use the:
open_basedir .:/tmp:/usr/local/lib/php:/home/12345:/home/theirdomain.com
as a security measure. All sites reside in:
/home/12345
(Where 12345 is their userid), and then their domain is symlinked to it for ease of use:
/home/theirdomain.com
What we've found is after upgrading, whenever a user uses
file_exists("/home/theirdomain.com/file.ext")
If the file does NOT exist, then it generates an error like this:
Warning: file_exists(): open_basedir restriction in effect.
File(/home/theirdomain.com/docs/notthere.txt) is not within the allowed path(s):
(.:/tmp:/usr/local/lib/php:/home/12345:/home/theirdomain.com/) in /home/12345/www/docs/test.php on
line 3
To combat this, as noted elsewhere change:
if (file_exists("/home/theirdomain.com/file.ext"))
to
if(file_exists(realpath("/home/theirdomain.com/file.ext"))
Hope that saves people some hair-pulling!!
-Andy