3 ms·
This bug is nothing to do with putting code in the web root. If you miss the opening <?php tag out in any file, regardless of whether it's in the web root, it w
by russss 16y ago
This bug is nothing to do with putting code in the web root. If you miss the opening <?php tag out in any file, regardless of whether it's in the web root, it will get printed straight out to the browser.
- brown9-2 16y agoThis sounds like "insecure by default" to me - you have to have the opening stanza correct in order for the file contents to be treated as code. Perhaps a more secure idea would be to require an opening stanza for the reverse - for content that should simply be printed to standard out? i.e. <?out to make content that should be outputed, not <?php for content that should be interpreted.
- deleted 16y ago[deleted]
- wladimir 16y agoFiles outside the web root are not accessible by the user via HTTP, so I don't see the issue with that? Unless you include it from somewhere in the web root, but that's the other insecure-by-default behaviour I was hinting at. With a secure-by-default web framework, it's not possible to get the code to show at all because it's not intermingled with the content.
- russss 16y agoIf there are no PHP files in the web root then what does your web site do? Every block of PHP code must begin with '<?php', regardless of where it's located, or whether it's included from another file. I do agree with you that this is a silly behaviour. But it's nothing to do with the web root.