4 ms·
I guarantee you that Tumblr has display_errors = Off. This wasn't a display_errors related fuckup, it was a missed opening PHP tag.
by russss 16y ago
I guarantee you that Tumblr has display_errors = Off. This wasn't a display_errors related fuckup, it was a missed opening PHP tag.
- nbpoole 16y agoWell, based on the code that was dumped, it looks like they're using their own error handler which was ignoring display_errors (search for "Use of undefined constant" in the dump).
- CWIZO 16y agoThat custom error handler was never set, because the code you see above never even executed. The reason was, like said many times already, a miss-typed opening PHP tag, which tells PHP where PHP code is. If that tag is missing or miss-typed the code is just returned to the browser like HTML. The point is that no server configuration can save you from an error like this.
- nbpoole 16y agoIf the custom error handler was never set, the PHP notices wouldn't look like that.
- moe 16y agoThe point is that no server configuration can save you from an error like this. Huh? Yes you can protect against errors like this; http://news.ycombinator.com/item?id=2343675 http://news.ycombinator.com/item?id=2343675
- eli 16y agoWell, off the top of my head, mod_security has rules that scan outgoing data for password or code leakage. A deployment strategy that requires testing that pages show what you expect them to show would also likely catch it.