Re: [PHP4BETA] PHP 4.0b3 released
| From: | Stanislav Malyshev | Date: | Thu, 18 Nov 1999 08:55:33 +0000 |
| Subject: | Re: [PHP4BETA] PHP 4.0b3 released | ||
| Groups: | php.version4 | ||
| Request: | Send a blank email to php-version4+get-6428@lists.php.net to get a copy of this message | ||
>> What I want is:
>>
>> if( ( fileowner( ThisScript ) == fileowner( TargetFile )) OR # Existing check
>> ( fileowner( TargetFile ) == 'root' AND # Owned by root
>> !(fileperms( TargetFile ) && octdec('003') AND # Not group/world
>> writable*
>> fileowner( TargetDir ) == 'root' AND # Dir owned by root
>> !(fileperms( TargetDir ) && octdec('002') # Not group/world
>> writable
>> )) { # OK To act
>>
>> * I'm not sure if I want to use 003, 033 or 0113 on file permissions
>> test. I see no reason for any php library to be executable so 0111
>> should probably be in it. I think it is best to allow the group to
>> write the file too. Root will just have to be careful who is in the
>> group when creating common library files.
This doesn't sound good. First, you not always are giving root to
a site webmaster (and on virtual server setup - I mean real full-blown
virtualized hosting - you *never* do this). Second, it seems too
much trouble to administer. Why don't just make configurable admin
parameter lib_dir, which can be set by sysadmin and will tell PHP that
it's safe to include/require (but not read or otherwise access) files in
that directory? This could, however, constitute problem for those modules
who actually read files (templates). Maybe there shold be execute-only
and read-and-execute (if you can read, you can execute anyway) library dirs?
--
Stanislav Malyshev Zend Technologies Ltd.
stas@zend.com http://www.zend.com/
050-624945