phpgroupware-users
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Phpgroupware-users] Re: Filemanager and the Document-root


From: Dave Hall
Subject: Re: [Phpgroupware-users] Re: Filemanager and the Document-root
Date: Sat, 07 Oct 2006 23:39:39 +1000

On Sat, 2006-10-07 at 06:26 -0700, chackie-lee wrote:
> 
> > It seems to me, that they use something like /home/nnn/user/ as > the doc
> > root?
> Yeah, thats right. My home-path is /home/15/dwdanied
> 
> > What is your document root and home directory?  Feel free to
> > munge it if you have to.
> The problem is, that the home directory is the same as the document root. 
> And I think, a lot of Webspace-Provider make it like bytecamp.net.
> 

That is the first time I have seen a host do that, and I have seen some
weird hosting setups.  It also means that you have no choice but to
store potentially sensitive data either in the document root or n a
shared area - neither of which are good for security.

> Why does the phpGroupware uses this procedure for the 
> filemanger/User-/group-file?? 
> I have tested allot of them, and this one is the only one, which do it this 
> way. 
> 

It is a basic security pre caution, it would be possible for someone to
find the directory you are storing the files in and then access them.
This way they can only access files via the webgui.

I am aware of at least 2 other web based groupware suites written in php
which have this restriction.

> BTW: Any ideas, why DB-operations are so slow? Every Page-load needs 4-5 
> seconds. Other groupwares need 0.5 sec only.

No.  I have not found phpgw to be that slow.  How are you obtaining the
execution times for comparison?

Cheers

Dave





reply via email to

[Prev in Thread] Current Thread [Next in Thread]