Re: [PHP4BETA] Re: [PHP3] mkdir Bug?

From: Date: Thu, 22 Jul 1999 09:41:50 +0000
Subject: Re: [PHP4BETA] Re: [PHP3] mkdir Bug?
References: 1  Groups: php.version4 
Request: Send a blank email to php-version4+get-2504@lists.php.net to get a copy of this message
On Thu, 22 Jul 1999, Matthew Hawkins wrote: }Last Thursday at 14:04:21, I thought I heard Vivek Awasthi say: }> i'm having the same problem with my script. It always makes the dir with }> 755 mode? }> couldn't figure it out. } }I'd consider it a security feature, even though I usually loathe computer }programs that think they know better than you do. In this case, I'd }make an exception. Only one directory needs to be mode 777, and that's }/tmp which would exist long before you install php (making the mkdir() }pointless). No. I have had for example the problem, that there is a document-root which is also used as FTP-pub-directory. This is a more or less often used configuration; it makes sense, cause you have access with two methods to the same amount of data. Users can upload as both, over HTTP and FTP. In HTTP I have written an upload-tool, which gives the users simple access to the directories (create dirs, delete dirs, upload files, rename files, delete files). The problem is, that the group www must have the same rights as group ftp, so the group must be writeable, otherwise it dosn't work that a directory is created with user "wwwrun.www" and a ftp-user "hugo.ftp" can upload into this dir, too. The only way I found to create a new directory via PHP with the correct rights is the following: $newdir=RSlash("$udir[absnow]/$newdirname"); if (file_exists($newdir)) { $error="Directory exists"; } else { mkdir($newdir,0765); # 765 -> senceless, takes always 755 exec("chmod g+w $newdir"); # this isn't nice but thats default security # feature of PHP } So I ask: Why is this "feature" built in, when it can be overridden by normal shell-commands and if no special security is needed? -- SSilk - Alexander Aulbach - Herbipolis/Frankonia Minoris - (0931)22032

« previous php.version4 (#2504) next »