Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM
Nico Williams <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <CAK3OfOguiCHVse3wBu6k01wf4t9BUQ2MqY_-BHiK5cFRJN6SGg@mail.gmail.com> |
On Thu, Oct 27, 2011 at 12:55 PM, <[email protected]> wrote: > On Thu, Oct 27, 2011 at 09:43:39AM -0700, Russ Allbery wrote: >> > Unfortunately, to be able to fulfil the request of a user, Apache has to >> > read the PHP code and the (possibly user-specific) data which are the > >> Correct. And often that's data that the user should not have access to, > > Surely we should not "call http daemons proxies" just because they can > be used as such. On the other side Nico apparently meant that very kind > of uses when an Apache has the "user proxying" role, then the term and > the conclusions are reasonable. Never mind, all of us seem to understand > both each other and the implications. I did not mean to exclude uses of web servers where serving files is not the point (don't forget WebDAV, BTW).