Commit b4b958c4 authored by Joshua Slive's avatar Joshua Slive
Browse files

Backport:

My last effort was a little too succinct and not quite precise
enough.  Try being more explicit.

This does leave the danger that people will clip the <Location>
example as the proper way to do things, when they should be
reading on to the <Directory> example.  The <Location> example
is only correct when used in conjunction with Alias.



git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@433023 13f79535-47bb-0310-9956-ffa450edef68
parent 845c3a8a
Loading
Loading
Loading
Loading
+18 −6
Original line number Original line Diff line number Diff line
@@ -355,15 +355,15 @@ target as a CGI script</td></tr>
    is essentially equivalent to:</p>
    is essentially equivalent to:</p>
    <div class="example"><p><code>
    <div class="example"><p><code>
      Alias /cgi-bin/ /web/cgi-bin/<br />
      Alias /cgi-bin/ /web/cgi-bin/<br />
      &lt;Directory /web/cgi-bin &gt;<br />
      &lt;Location /cgi-bin &gt;<br />
      <span class="indent">
      <span class="indent">
      SetHandler cgi-script<br />
      SetHandler cgi-script<br />
      Options +ExecCGI<br />
      Options +ExecCGI<br />
      </span>
      </span>
      &lt;/Directory&gt;
      &lt;/Location&gt;
    </code></p></div>
    </code></p></div>


    <div class="note">It is safer to avoid placing CGI scripts under the
    <div class="warning">It is safer to avoid placing CGI scripts under the
    <code class="directive"><a href="../mod/core.html#documentroot">DocumentRoot</a></code> in order to
    <code class="directive"><a href="../mod/core.html#documentroot">DocumentRoot</a></code> in order to
    avoid accidentally revealing their source code if the
    avoid accidentally revealing their source code if the
    configuration is ever changed.  The
    configuration is ever changed.  The
@@ -371,8 +371,20 @@ target as a CGI script</td></tr>
    URL and designating CGI scripts at the same time.  If you do
    URL and designating CGI scripts at the same time.  If you do
    choose to place your CGI scripts in a directory already
    choose to place your CGI scripts in a directory already
    accessible from the web, do not use
    accessible from the web, do not use
    <code class="directive">ScriptAlias</code>.  Instead, use <code class="directive"><a href="../mod/core.html#directory">&lt;Directory&gt;</a></code>, <code class="directive"><a href="../mod/core.html#sethandler">SetHandler</a></code>, and <code class="directive"><a href="../mod/core.html#options">Options</a></code> as shown in the second example
    <code class="directive">ScriptAlias</code>.  Instead, use <code class="directive"><a href="../mod/core.html#directory">&lt;Directory&gt;</a></code>, <code class="directive"><a href="../mod/core.html#sethandler">SetHandler</a></code>, and <code class="directive"><a href="../mod/core.html#options">Options</a></code> as in:
    above.</div>
    <div class="example"><p><code>
      &lt;Directory /usr/local/apache2/htdocs/cgi-bin &gt;<br />
      <span class="indent">
      SetHandler cgi-script<br />
      Options ExecCGI<br />
      </span>
      &lt;/Directory&gt;
    </code></p></div>
    This is necessary since multiple <var>URL-paths</var> can map
    to the same filesystem location, potentially bypassing the
    <code class="directive">ScriptAlias</code> and revealing the source code
    of the CGI scripts if they are not restricted by a 
    <code class="directive"><a href="../mod/core.html#directory">Directory</a></code> section.</div>




<h3>See also</h3>
<h3>See also</h3>
+17 −5
Original line number Original line Diff line number Diff line
@@ -348,15 +348,15 @@ target as a CGI script</description>
    is essentially equivalent to:</p>
    is essentially equivalent to:</p>
    <example>
    <example>
      Alias /cgi-bin/ /web/cgi-bin/<br />
      Alias /cgi-bin/ /web/cgi-bin/<br />
      &lt;Directory /web/cgi-bin &gt;<br />
      &lt;Location /cgi-bin &gt;<br />
      <indent>
      <indent>
      SetHandler cgi-script<br />
      SetHandler cgi-script<br />
      Options +ExecCGI<br />
      Options +ExecCGI<br />
      </indent>
      </indent>
      &lt;/Directory&gt;
      &lt;/Location&gt;
    </example>
    </example>


    <note>It is safer to avoid placing CGI scripts under the
    <note type="warning">It is safer to avoid placing CGI scripts under the
    <directive module="core">DocumentRoot</directive> in order to
    <directive module="core">DocumentRoot</directive> in order to
    avoid accidentally revealing their source code if the
    avoid accidentally revealing their source code if the
    configuration is ever changed.  The
    configuration is ever changed.  The
@@ -367,8 +367,20 @@ target as a CGI script</description>
    <directive>ScriptAlias</directive>.  Instead, use <directive
    <directive>ScriptAlias</directive>.  Instead, use <directive
    module="core" type="section">Directory</directive>, <directive
    module="core" type="section">Directory</directive>, <directive
    module="core">SetHandler</directive>, and <directive
    module="core">SetHandler</directive>, and <directive
    module="core">Options</directive> as shown in the second example
    module="core">Options</directive> as in:
    above.</note>
    <example>
      &lt;Directory /usr/local/apache2/htdocs/cgi-bin &gt;<br />
      <indent>
      SetHandler cgi-script<br />
      Options ExecCGI<br />
      </indent>
      &lt;/Directory&gt;
    </example>
    This is necessary since multiple <var>URL-paths</var> can map
    to the same filesystem location, potentially bypassing the
    <directive>ScriptAlias</directive> and revealing the source code
    of the CGI scripts if they are not restricted by a 
    <directive module="core">Directory</directive> section.</note>


</usage>
</usage>
<seealso><a href="../howto/cgi.html">CGI Tutorial</a></seealso>
<seealso><a href="../howto/cgi.html">CGI Tutorial</a></seealso>