From: pdontthink Date: Wed, 25 Mar 2020 00:20:42 +0000 (+0000) Subject: Document $php_self_pattern and $php_self_replacement X-Git-Url: https://vcs.fsf.org/?a=commitdiff_plain;h=cb8cf9f9ceede7cba6fb0aa76fe44f2735b66721;p=squirrelmail.git Document $php_self_pattern and $php_self_replacement git-svn-id: https://svn.code.sf.net/p/squirrelmail/code/trunk/squirrelmail@14853 7612ce4b-ef26-0410-bec9-ea0150e637f0 --- diff --git a/doc/ChangeLog b/doc/ChangeLog index 00c90fad..4af06e17 100644 --- a/doc/ChangeLog +++ b/doc/ChangeLog @@ -431,6 +431,14 @@ Version 1.5.2 - SVN (see notes in config/config_local.example.php for more details) - Added handling for RCDATA and RAWTEXT elements in HTML sanitizer [CVE-2019-12970] + - Added the ability to modify of the value of the global $PHP_SELF + variable used throughout the SquirrelMail code (though less so + in version 1.5.2). The administrator may do so by adding the + configuration settings $php_self_pattern and $php_self_replacement + to config/config_local.php, where the pattern should be a full + regular expression including the delimiters. This may be helpful + when the web server sees traffic from a proxy so the normal + $PHP_SELF does not resolve to what it should be for the real client. Version 1.5.1 (branched on 2006-02-12) --------------------------------------