4 ms·
Yes, any half-decent PHP framework will have some solution for this. CodeIgniter, in particular, gets around it with a combination of .htaccess files in every
by vec 13y ago
Yes, any half-decent PHP framework will have some solution for this. CodeIgniter, in particular, gets around it with a combination of .htaccess files in every root directory, index.html pages in every subdirectory, and a boilerplate `defined('BASEPATH') OR exit('No direct script access allowed');` snippet at the top of every file. As long as the developer continues this convention through all their additions, this works quite well and is very secure and stable. It's also completely unnecessary. And it breaks if you want to host under nginx or lighttpd or anything that's not apache.
The point is that this is a problem web frameworks don't have to have in the first place. It is relatively easy to fix, if you know how, but it creates boilerplate code and adds potential for security holes for literally no benefit. The ability to heal a self-inflicted wound is a poor substitute substitute for not being injured in the first place.
- tmzt 13y agoThe downloadable distribution of CodeIgniter and many other PHP frameworks have those file and boilerplate to protect badly configured Apache setups where the user just unzips the downloaded distribution into public_html. If you have .php files handled by PHP, or you have the mod rewrite htaccess rules enabled, the PHP files won't be exposed to the user. None of these are necessary if you have properly configured your web server.