# Auto user-specific php.ini for suPHP

**URL:** <https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646>\
**Category:** Feature Requests\
**Created:** [May 28, 2010, 11:06pm UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646 "2010-05-28T23:06:15Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lightfoot](https://forums.interworx.com/letter_avatar_proxy/v4/letter/l/8e8cbc/32.png) [@Lightfoot](https://forums.interworx.com/u/Lightfoot)\
**Post date:** [May 28, 2010, 11:06pm UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/1 "2010-05-28T23:06:15Z")

</div>

Before changing over to suPHP I was using a custom vhost-base.conf file to automatically generate the PHP value for open\_basedir per virtual host upon new siteworx account creation, like this:

php\_admin\_value open\_basedir “\<\<WEBROOT\>\>:/tmp”

Now with suPHP I have to create the /home/user/etc/ folder and php.ini file in there and set the appropriate permissions manually.

Are there any plans to allow auto generation of the per-user php.ini files with some custom default values?

---

<div class="post-metadata">

**Author:** ![EverythingWeb](https://forums.interworx.com/letter_avatar_proxy/v4/letter/e/8baadc/32.png) [@EverythingWeb](https://forums.interworx.com/u/EverythingWeb)\
**Post date:** [June 2, 2010, 5:44am UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/2 "2010-06-02T05:44:30Z")

</div>

Second this! 🙂

---

<div class="post-metadata">

**Author:** ![Evanion](https://forums.interworx.com/letter_avatar_proxy/v4/letter/e/ee59a6/32.png) [@Evanion](https://forums.interworx.com/u/Evanion)\
**Post date:** [July 22, 2011, 7:47am UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/3 "2011-07-22T07:47:11Z")

</div>

Third!  
there aer several php properties that i would like the user to be able to turn off.  
Like: show\_source, system, shell\_exec, passthru, exec, phpinfo, popen, proc\_open, allow\_url\_fopen and set open\_basedir (or default it to their home folder so their CMS systems don’t bug them about it).

---

<div class="post-metadata">

**Author:** ![subxtech](https://forums.interworx.com/letter_avatar_proxy/v4/letter/s/f4b2a3/32.png) [@subxtech](https://forums.interworx.com/u/subxtech)\
**Post date:** [August 15, 2011, 1:33am UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/4 "2011-08-15T01:33:31Z")

</div>

forth vote here.

---

<div class="post-metadata">

**Author:** ![gerwin](https://forums.interworx.com/letter_avatar_proxy/v4/letter/g/a6a055/32.png) [@gerwin](https://forums.interworx.com/u/gerwin)\
**Post date:** [January 26, 2012, 6:38am UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/5 "2012-01-26T06:38:01Z")

</div>

Another vote.

---

<div class="post-metadata">

**Author:** ![IWorx-Dan](https://forums.interworx.com/letter_avatar_proxy/v4/letter/i/d2c977/32.png) [@IWorx-Dan](https://forums.interworx.com/u/IWorx-Dan)\
**Post date:** [January 26, 2012, 2:39pm UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/6 "2012-01-26T14:39:54Z")

</div>

Hello Ladies and Gents,

Not sure how we haven’t seen this yet, but I have taken the request and added it to our request tracker. Definitely sounds like a good idea!

---

<div class="post-metadata">

**Author:** ![gerwin](https://forums.interworx.com/letter_avatar_proxy/v4/letter/g/a6a055/32.png) [@gerwin](https://forums.interworx.com/u/gerwin)\
**Post date:** [January 27, 2012, 5:29am UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/7 "2012-01-27T05:29:54Z")

</div>

Dan that would be nice! Right now it’s possible to overwrite all PHP setting (such as memory\_limit) with PHP’s ini\_set command. It would make our staff so happy 🙂  
My suggestions to set the following parameters per site and default:

- register\_globals
- allow\_url\_fopen
- allow\_url\_include
- magic\_quotes\_gpc
- register\_long\_arrays
- memory\_limit
- upload\_max\_filesize
- post\_max\_size
- max\_execution\_time
- max\_input\_time

---

<div class="post-metadata">

**Author:** ![gerwin](https://forums.interworx.com/letter_avatar_proxy/v4/letter/g/a6a055/32.png) [@gerwin](https://forums.interworx.com/u/gerwin)\
**Post date:** [February 15, 2012, 3:53am UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/8 "2012-02-15T03:53:38Z")

</div>

Hi Guys,

We made a little-temp-fix for the suPHP problem which:

[LIST=1]

- creates a /home/\<user\>/etc directorie in the siteworx user directory and copies /etc/php.ini to this IF not already existst.
- changes owner of php.ini to root:root (we do not allow our customers to make changes to php.ini themselves).
- fixes the session directory in the php.ini (sessions will be placed in /home/\<user\>/tmp directorie of the the siteworx user) [/LIST] We run this script every 5 minutes. As said before it's a work-around script so don't expect rocket science. If it makes you happy,I am happy :-)

```auto

#! /bin/bash

function get-dir-list()
{
    local -a info

    while read -a info; do
        echo "/home/${info[1]}"
    done < <( nodeworx -u -n -c Siteworx -a listAccounts )
}

while read dir; do
    if etc="$dir/etc"; [[! -d "$etc"]]; then
        mkdir "$etc"
        # Do not change ownership to owner,
        # or an owner could remove php.ini
        # and replace it with its own... :P
        chown root:root "$etc"
    fi

    if tmp="$dir/tmp"; [[! -d "$tmp"]]; then
        mkdir "$tmp"
        chown --reference="$dir" "$tmp"
        chmod 01755 "$tmp"
    fi

    if ini="$etc/php.ini"; [[! -f "$ini"]]; then
        cp /etc/php.ini "$ini"
        chown root:root "$ini"
        chmod 0444 "$ini"
    fi

    read s < <( sed -nr 's/^ *session[.]save_path *= *(.*)$/\1/p' "$ini" )
    if [["$s" != "$tmp"]]; then
        sed -ri 's#^( *session[.]save_path *= *).*$#\1'"$tmp"'#' "$ini"
    fi
done < <( get-dir-list )

```

---

<div class="post-metadata">

**Author:** ![IWorx-Matt](https://forums.interworx.com/user_avatar/forums.interworx.com/iworx-matt/32/14_2.png) [@IWorx-Matt](https://forums.interworx.com/u/IWorx-Matt)\
**Post date:** [April 29, 2013, 3:33pm UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/9 "2013-04-29T15:33:22Z")

</div>

Event Hooks Plugin Script

Based on gerwin’s excellent cron script above, the following can be integrated with our Event Hooks plugin to automate the creation of the necessary files and directories:

```auto

#!/bin/bash
#
# INSTALLATION:
#
# First, ensure the InterWorx CLI is installed via 'yum install interworx-cli'
# 
# Install this script at /usr/local/bin/enable_session_save_path.sh
# 
# Enable the Event Hooks plugin in NodeWorx.
# Add the following line to your InterWorx Event Hook Configuration:
# 
# Ctrl_Nodeworx_Siteworx add /usr/local/bin/enable_session_save_path.sh
# 
# Ensure that both this file *and* the Event Hook config are both readable
# and executable by the iworx user:
# 
# chmod 0770 /usr/local/bin/enable_session_save_path.sh
# chown iworx /usr/local/bin/enable_session_save_path.sh
# 
# In order for this script to run successfully, the iworx user
# must be added to the sudoers file. This can be done as follows:
# 
# Run 'visudo'
# Append these lines: 
#
# %iworx ALL=(ALL) NOPASSWD:SETENV: /bin/bash -p /usr/local/bin/enable_session_save_path.sh
# Defaults:%iworx !requiretty
#
# Save and exit visudo

if [["$iw_uniqname" == ""]]; then
  exit 1
fi

if [["$(id -u)" != "0"]]; then
  self="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )/$(basename $0)"
  sudo -E bash -p $self
  exit 0
fi

dir="/home/$iw_uniqname"

if etc="$dir/etc"; [[! -d "$etc"]]; then
        mkdir "$etc"
        # Do not change ownership to owner,
        # or an owner could remove php.ini
        # and replace it with its own
        chown root:root "$etc"
fi

if tmp="$dir/tmp"; [[! -d "$tmp"]]; then
        mkdir "$tmp"
        chown --reference="$dir" "$tmp"
        chmod 01755 "$tmp"
fi

if ini="$etc/php.ini"; [[! -f "$ini"]]; then
        cp /etc/php.ini "$ini"
        chown root:root "$ini"
        chmod 0444 "$ini"
fi

read s < <( sed -nr 's/^ *session[.]save_path *= *(.*)$/\1/p' "$ini" )
if [["$s" != "$tmp"]]; then
        sed -ri 's#^( *session[.]save_path *= *).*$#\1'"$tmp"'#' "$ini"
fi

```

---

<div class="post-metadata">

**Author:** ![Evanion](https://forums.interworx.com/letter_avatar_proxy/v4/letter/e/ee59a6/32.png) [@Evanion](https://forums.interworx.com/u/Evanion)\
**Post date:** [April 30, 2013, 1:29am UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/10 "2013-04-30T01:29:36Z")

</div>

Ah, nice … can easily change it to use another php.ini. Thats good.

---

<div class="post-metadata">

**Author:** ![reza](https://forums.interworx.com/letter_avatar_proxy/v4/letter/r/b4bc9f/32.png) [@reza](https://forums.interworx.com/u/reza)\
**Post date:** [July 27, 2013, 6:27am UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/11 "2013-07-27T06:27:23Z")

</div>

Matt,

I tried your script there with the Event Hooks on Interworx 5 beta 6 release, running on Cloud Linux.  
The script never run at all, can you help?  
Here is the message from iworx.log

```auto
2013-07-27 09:25:26.47455 [ts9omg-wcn5-ktnu-WEB] [INFO] : hook prog not executable by iworx: /usr/local/bin/enable_session_save_path.sh : /xhr.php 
2013-07-27 09:25:26.69654 [ts9omg-fvt4-rk7m-PHP] [INFO] : 139.228.32.134 routing: Ctrl_Nodeworx_Siteworx -> searchCommit : /xhr.php 

```

How can I use your script to make the php.ini available to each SiteWorx account, and also provide a place for the php sessions?

Thank you,  
Reza

---

<div class="post-metadata">

**Author:** ![ambrozy](https://forums.interworx.com/letter_avatar_proxy/v4/letter/a/8dc957/32.png) [@ambrozy](https://forums.interworx.com/u/ambrozy)\
**Post date:** [September 17, 2013, 12:59am UTC](https://forums.interworx.com/t/auto-user-specific-php-ini-for-suphp/12646/12 "2013-09-17T00:59:52Z")

</div>

reza: what is fixed?
