It's needed to connect to databases with authentication. What would you suggest?
A solution would be to have a .ini-like (or some other simple-to-parse format) config file and PHP code to read its contents. PHP code could be leaked, but config file contents wouldn't.
Deleted comment
Edit: I've tested this:
$ php -v
PHP 5.2.6-3ubuntu4.6 with Suhosin-Patch 0.9.6.2 (cli) (built: Sep 16 2010 19:51:25)
Copyright (c) 1997-2008 The PHP Group
Zend Engine v2.2.0, Copyright (c) 1998-2008 Zend Technologies
$ cat test.php
<?php
require "/tmp/test2.php";
?>
$ cat /tmp/test2.php
i?php
define("TEST", "test");
?>
$ GET http://localhost/test.php
i?php
define("TEST", "test");
?>I think. I haven't seriously used php since 2003 or so.
If you want to avoid that possibility, you can use a non-PHP format (eg: YAML) and parse it.
If that i?php blunder happened to me, my users would see 10 lines of code. One include for the framework (which lives outside the web root), plus three calls to get the framework to handle the current request.
Those 10 lines would be totally unproblematic
Of course, you are completely right, it should still be inaccessible from the web.