Smarty Forum Index Smarty
WARNING: All discussion is moving to https://reddit.com/r/smarty, please go there! This forum will be closing soon.

{php} not secure?

 
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Smarty Forum Index -> General
View previous topic :: View next topic  
Author Message
mastab0323
Smarty Rookie


Joined: 01 Jul 2005
Posts: 27

PostPosted: Sat Jul 02, 2005 12:49 am    Post subject: {php} not secure? Reply with quote

I have a centralized CMS software where a client can login and manage their content, including altering their website templates and creating their own styles for this CMS software. They do not have access to any of the php code, but only the software, and we allow them to style the software as they please using the smarty template engine, and the smarty template files are placed into their own personal directory and loaded once they log in. I dont want them to have the ability to alter any of the files or php code.

Couldnt they do this

{php}
`rm index.php`
{/php}

or something along those lines?

How do I keep them from doing this and keep my code and my files secure?

Thanks for your help.
Back to top
View user's profile Send private message
boots
Administrator


Joined: 16 Apr 2003
Posts: 5611
Location: Toronto, Canada

PostPosted: Sat Jul 02, 2005 12:57 am    Post subject: Reply with quote

Quote:
How do I keep them from doing this and keep my code and my files secure?


A: By enabling security mode. See: http://smarty.php.net/manual/en/variable.security.php

There are certain implications to turning it on and there are also several switches which you can use to achieve various levels of granularity. It is covered in the manual, but of course, do ask if you have difficulties.
Back to top
View user's profile Send private message
Display posts from previous:   
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Smarty Forum Index -> General All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group
Protected by Anti-Spam ACP