We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 10691
    • 36 Posts
    I have a website with a phpBB3-forum and a MODx-CMS, looking like:
    phpBB: mydomain/forums/
    MODx: mydomain/modx/
    I’d like to place some information about the forum (latest topics, whosonline, etc) on a sidepanel in the MODx-part. For that, I made a php-file wich starts with:
    <?php
    define('IN_PHPBB', true);
    $phpbb_root_path = (defined('PHPBB_ROOT_PATH')) ? PHPBB_ROOT_PATH : '../forums/'; 
    $phpEx = substr(strrchr(__FILE__, '.'), 1);
    include($phpbb_root_path . 'common.' . $phpEx);
    
    // Start session management
    $user->session_begin();
    $auth->acl($user->data);
    $user->setup();
    
    //further stuff

    When I call that file directly (pointing the browser to mydomain/modx/assets/site/page.php) I get a perfect result. But when I include it in a snippet (literally using a php-include for the moment) it results in this error:
    « MODx Parse Error »
    MODx encountered the following error while attempting to parse the requested resource: 
    « PHP Parse Error » 
      
    PHP error debug 
      Error:  include() [function.include]: open_basedir restriction in effect. File(../../../forums/common.php) is not within the allowed path(s): (/home/swordfac:/usr/lib/php:/usr/local/lib/php:/tmp)   
      Error type/ Nr.:  Warning - 2   
      File:  /home/swordfac/public_html/modx/assets/site/last_topics.php   
      Line:  11   
      Line 11 source:  include($phpbb_root_path . 'common.' . $phpEx);    
      
    Parser timing 
      MySQL:  0.0011 s (3 Requests) 
      PHP:  0.0238 s   
      Total:  0.0249 s   
    
    "Not within the allowed path(s)" apperently. I’m guessing that relates to that it connects with files outside MODx? Could someone inform me on how to solve that?


      • 10449
      • 956 Posts
      PHP seems to be running in safe mode: http://www.php.net/features.safe-mode

      Often, there’s not a lot you can do about it, especially on shared hosting accounts. You could try to change those settings in php.ini or .htaccess. But usually overriding this setting is not supported either with such hosters.

      Try to hardcode the paths and use full path-names. Or contact your hoster.
        • 10691
        • 36 Posts
        Thanks, but that’s not the problem. Phpinfo tells me that safe_mode is off.
          • 10449
          • 956 Posts
          Well, the open_basedir restriction is pretty much the same, i.e. if your host has deactivated it, I don’t think you can override it from within a script. From the page I linked above:


          open_basedir string

          Limit the files that can be opened by PHP to the specified directory-tree, including the file itself. This directive is NOT affected by whether Safe Mode is turned On or Off.

          When a script tries to open a file with, for example, fopen() or gzopen(), the location of the file is checked. When the file is outside the specified directory-tree, PHP will refuse to open it. All symbolic links are resolved, so it’s not possible to avoid this restriction with a symlink. If the file doesn’t exist then the symlink couldn’t be resolved and the filename is compared to (a resolved) open_basedir .

          The special value . indicates that the working directory of the script will be used as the base-directory. This is, however, a little dangerous as the working directory of the script can easily be changed with chdir().

          In httpd.conf, open_basedir can be turned off (e.g. for some virtual hosts) the same way as any other configuration directive with "php_admin_value open_basedir none".

          Under Windows, separate the directories with a semicolon. On all other systems, separate the directories with a colon. As an Apache module, open_basedir paths from parent directories are now automatically inherited.

          The restriction specified with open_basedir is actually a prefix, not a directory name. This means that "open_basedir = /dir/incl" also allows access to "/dir/include" and "/dir/incls" if they exist. When you want to restrict access to only the specified directory, end with a slash. For example: "open_basedir = /dir/incl/"

          The default is to allow all files to be opened.

          Note: As of PHP 5.3.0 open_basedir can be tightened at run-time. This means that if open_basedir is set to /www/ in php.ini a script can tighten the configuration to /www/tmp/ at run-time with ini_set()
            • 10691
            • 36 Posts
            Phpinfo tells me at open_basedir:
            /home/swordfac:/usr/lib/php:/usr/local/lib/php:/tmp
            while master value is no value. As I understand, I could contact my host about this? (I do have shared hosting indeed).

            And if I go the php.ini-way, how should I do that? (ini_set(), but how exactly?)
              • 10691
              • 36 Posts
              Well, in the end I solved it like this:
              /modx/index.php calls /modx/forum.php
              /modx/forum.php executes the script and writes the html-result to /modx/result.php (php because I need headers for IE).
              /modx/result.php is included in a snippet.

              This works fine, but I still don’t understand why I can do this while I can’t directly execute it from a snippet.