代码之家  ›  专栏  ›  技术社区  ›  mercutio

重写规则-超出docroot

  •  1
  • mercutio  · 技术社区  · 17 年前

    假设以下目录结构,

    htdocs/
      images/
      css/
      .htaccess
    system/
      index.php
      ...
    

    有没有在docroot之外重写的方法?

    2 回复  |  直到 17 年前
        1
  •  4
  •   rojoca    17 年前

    许多框架所做的是使用“重写”将所有请求路由到一个文件,在这个文件中您可以自己执行更复杂的路由。例如.htaccess文件可能是:

    # ignore anything that's an actual file (eg CSS, js, images) 
    RewriteCond %{DOCUMENT_ROOT}%{REQUEST_URI} !-f
    # redirect all other traffic to the index page
    RewriteRule ^.*$ index.php [L]
    

    其中index.php位于文档根目录(htdocs/index.php)中,您可以在适当的地方从中安全地包含System/index.php。

        2
  •  3
  •   Robert K    17 年前

    不,如果没有潜在的巨大风险,您无法在docroot之外进行路由。

    你应该把 index.php 在 htdocs 然后在那里重写它,而不是在外面。如果您要重写来处理索引,访问docroot之外的文件,并且犯了一个小错误,那么任何重写请求字符串的黑客都有可能利用这个错误。不漂亮!