[Tiki-devel] Security setting and php.ini

Bernard Sfez via TikiWiki-devel <[email protected]>
Newsgroups gmane.comp.cms.tiki.devel
Message-ID <[email protected]>
Hello,

(Playing a little out of my league).

For a Tiki new admin I searched and reviewed some information about System Configuration and Risky Preferences.
I updated some doc pages and found something I didn’t noticed before at : https://doc.tiki.org/System-Configuration?latest=1&no_bl=y#Protecting_ini_file_content_when_stored_in_a_location_accessible_from_the_web

That suggest adding this to the file:

<?php
// This script may only be included - so it is better to die if called directly.
// Keep this block to avoid the content to be read from the internet.
if (strpos($_SERVER['SCRIPT_NAME'], basename(__FILE__)) !== false) {
	header('location: index.php');
	exit;
}
?>

When I did on 2 Tiki to test I ended with WSoD so I removed it and the Tiki worked back.

Is the information on Tiki doc correct ?
Subject to specific installation ?
Outdated ?

Thanks to help clarify.
Bernard




_______________________________________________
TikiWiki-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.