Skip to content

Release 3.1.0

Choose a tag to compare

@rekmus rekmus released this 17 Apr 16:44
· 4 commits to master since this release
070df5f

New

  • REQ() is now forward slash-agnostic
  • URI() accepting std::string
  • NPP_PHP macro. If defined, php files in res – if requested – are passed to php-cgi. It allows to execute PHP code straight from the resource directory. PHP code does not share Node++ sessions. Query strings, POST payload and cookies are passed over to php-cgi and likewise, cookies and redirections are passed back to the client. It's designed to enable quick and simple PHP support. Therefore the request payload is limited to 3 KiB and rendered response to NPP_OUT_BUFSIZE bytes, which is 128 KiB by default (NPP_MEM_SMALL).

NPP_PHP security considerations

  • The request is passed over to php-cgi only after confirming the requested php file exists in res directory.
  • By default, the PHPSESSID is the only cookie allowed and is sanitized using npp_filter_strict() before passing over to php-cgi. To enable passing all cookies, add NPP_PHP_ALL_COOKIES.
  • Query string and payload is sanitized using npp_filter_qs(). It practically means the only Content-type fully supported by NPP_PHP is www-form-urlencoded. Due to the way payload is passed to php-cgi, without this sanitization, the system would be open to shell attacks.