From 9d43481a47e01f91138984ff2f6f7b97f12281fe Mon Sep 17 00:00:00 2001 From: Fabien Potencier Date: Tue, 24 Jan 2017 12:20:25 -0800 Subject: [PATCH] added the web front controller to framework-bundle --- .../symfony/framework-bundle/web/index.php | 44 +++++++++++++++++++ 1 file changed, 44 insertions(+) create mode 100644 recipes/symfony/framework-bundle/web/index.php diff --git a/recipes/symfony/framework-bundle/web/index.php b/recipes/symfony/framework-bundle/web/index.php new file mode 100644 index 00000000..d7f79d0d --- /dev/null +++ b/recipes/symfony/framework-bundle/web/index.php @@ -0,0 +1,44 @@ +load(__DIR__.'/../.env'); +} + +if (getenv('APP_DEBUG')) { + // WARNING: You should setup permissions the proper way! + // REMOVE the following PHP line and read + // http://symfony.com/doc/current/book/installation.html#checking-symfony-application-configuration-and-setup + umask(0000); + + // This check prevents access to debug front controllers that are deployed by accident to production servers. + // Feel free to remove this, extend it, or make something more sophisticated. + if (isset($_SERVER['HTTP_CLIENT_IP']) + || isset($_SERVER['HTTP_X_FORWARDED_FOR']) + || !(in_array(@$_SERVER['REMOTE_ADDR'], ['127.0.0.1', '::1']) || php_sapi_name() === 'cli-server') + ) { + header('HTTP/1.0 403 Forbidden'); + exit('You are not allowed to access this file. Check '.basename(__FILE__).' for more information.'); + } + + Debug::enable(); +} + +// Request::setTrustedProxiestTrustedHeaderName(Request::HEADER_FORWARDED, null); +// Request::setTrustedProxies(['0.0.0.0/0']); + +$kernel = new AppKernel(getenv('APP_ENV'), getenv('APP_DEBUG')); +$request = Request::createFromGlobals(); +$response = $kernel->handle($request); +$response->send(); +$kernel->terminate($request, $response);