Re: [PHP4BETA] PHP 4.0b3 released

From: Date: Thu, 18 Nov 1999 08:55:33 +0000
Subject: Re: [PHP4BETA] PHP 4.0b3 released
Groups: php.version4 
Request: Send a blank email to php-version4+get-6428@lists.php.net to get a copy of this message
>> What I want is: >> >> if( ( fileowner( ThisScript ) == fileowner( TargetFile )) OR # Existing check >> ( fileowner( TargetFile ) == 'root' AND # Owned by root >> !(fileperms( TargetFile ) && octdec('003') AND # Not group/world >> writable* >> fileowner( TargetDir ) == 'root' AND # Dir owned by root >> !(fileperms( TargetDir ) && octdec('002') # Not group/world >> writable >> )) { # OK To act >> >> * I'm not sure if I want to use 003, 033 or 0113 on file permissions >> test. I see no reason for any php library to be executable so 0111 >> should probably be in it. I think it is best to allow the group to >> write the file too. Root will just have to be careful who is in the >> group when creating common library files. This doesn't sound good. First, you not always are giving root to a site webmaster (and on virtual server setup - I mean real full-blown virtualized hosting - you *never* do this). Second, it seems too much trouble to administer. Why don't just make configurable admin parameter lib_dir, which can be set by sysadmin and will tell PHP that it's safe to include/require (but not read or otherwise access) files in that directory? This could, however, constitute problem for those modules who actually read files (templates). Maybe there shold be execute-only and read-and-execute (if you can read, you can execute anyway) library dirs? -- Stanislav Malyshev Zend Technologies Ltd. stas@zend.com http://www.zend.com/ 050-624945

« previous php.version4 (#6428) next »