Hello,
I have a new site in Evo 1.0.5 that is showing the register_globals set to ON warning in the configuration tab of the manager, but when I put a phpinfo.php file into the main directory, it shows register_globals as Off.
I have a php.ini file with "register_globals = Off" in the main directory and when I change this to On, the phpinfo file shows the change.
I can't get the host to do much to help me because they are seeing them as Off in the phpinfo file - can anyone tell me why this might be? Are they Off or On?
[ed. note: atype last edited this post 14 years, 4 months ago.]
Please check your .htaccess file for
php_flag register_globals on
If you see the above setting, turn it off, or remove the line to use the default of your web-server.
In addition, please install the latest version of Evolution, that is at this moment 1.0.6.
Gone away and found a better place to stay
Thanks for the reply, but if I add the line to .htaccess I get the 500 server error, so there is no register_globals setting in .htaccess.
And yes, the next step is to upgrade the site to 1.0.6 but was hoping to get everything right before, I guess I'll go ahead with upgrading first.
-
☆ A M B ☆
- 24,524 Posts
It all depends on where PHP is looking for its ini file. Generally speaking, with MODx we're only concerned with where it looks when running /manager/index.php. You may need to have a custom php.ini file in the web root, or even in the /manager/ directrory, since php.ini is not inherited within directories.
I've tried putting php.ini in the /manager/ and /manager/includes/ folder as well but then I get booted out of the manager, and can't log in again - I have captcha on the manager login page and it just keeps telling me "Captcha is not configured properly.", when it should be is.
Do these settings in the phpinfo() under system info tell me anything useful?
Configuration File (php.ini) Path: /etc/php5/cgi
Loaded Configuration File: /etc/php5/cgi/php.ini
The thing is, I have another site on the same server that has been fine (register_globals wise) for about a year and tells me the Loaded Configuration File is in /manager/ - but it doesn't have a register_globals setting in it. I don't have ftp access to the /etc/ folder.
-
☆ A M B ☆
- 24,524 Posts
A loaded configuration file doesn't necessarily have all of the directives. If the "loaded" php.ini file doesn't have a directive for register_globals = Off, then add it.
Yes, that's what I thought, but I can't access the /etc/ directory via FTP for this site and the host's support insists it's Off. I'll send the loaded config file path to them and insist - for about the fourth time - that they fix it. Thanks.
-
☆ A M B ☆
- 2,213 Posts
You may need to copy the entire php.ini file and adjust it. Give
http://tips-scripts.com/php_ini a try putting your desired changes in the php file.
Typically FTP accounts are locked to your user directory (ex: /home/username), giving access to anything above that would present security risks both in what you can access and the fact it's being accessed via FTP.
Could you share who the hosting company, they may have an unusual configuration that others have posted about/solved in the past?
OK, hopefully I have solved it.
I upgraded both sites to 1.0.6 and then they both showed the register_globals configuration warning - even the one that was OK before the upgrade.
So I did a search for php.ini in the backed up site - the other one that was good before the upgrade -and copied into the new manager(s) the various php.ini files I found in the main, assets, manager, actions, frames, includes, media and processors folders and the configuration notice is now gone. Strange thing (to me) is that only the one in the main directory has register_globals = Off in it - the others have magic_quotes_gpc = Off. Can anyone provide a (brief) explanation?
And thanks for everyones help.
-
☆ A M B ☆
- 24,524 Posts
In the manager, the only .php file you need to bother with is the /manager/index.php file, since all the rest are included in the code in the index.php file.
You may have a setting in your .htaccess file to tell the PHP engine where to look for php.ini files (if it's running as an Apache module). Otherwise, PHP will first look in its default location, then in any location specified in that default php.ini file, then in the directory where the .php file being run is located. So if you can put custom php.ini files in your site's directories, you only need one in the /manager/ directory.
Technically, it is recommended that every custom php.ini file be a complete copy, but often the custom files will only have the specific directives that are supposed to override the defaults.
Where and how this system of .ini files will work is dependent on how your server is configured. That's why it's often difficult for us to pinpoint exactly what is happening on any given installation.