[mod_python] server side parameters

Doug Epling depling at insightbb.com
Thu Jan 7 19:55:26 EST 2010


Apparently I am having some kind of conflict with Apache modsec.  Do the 
following lines from the Apache error_log mean anything?  Is this 
something I need to take up with my distro, which is Fedora Core?  Any 
help here will be appreciated; I have spent at least two days on this.

Thanks.

[Thu Jan 07 19:36:59 2010] [notice] Apache/2.2.14 (Unix) DAV/2 
mod_python/3.3.1 Python/2.6.2 mod_ssl/2.2.14 OpenSSL/1.0.0-fips-beta4 
mod_wsgi/2.5   configured -- resuming normal operations
[Thu Jan 07 19:36:59 2010] [info] Server built: Dec  3 2009 10:25:53
[Thu Jan 07 19:36:59 2010] [debug] prefork.c(1013): AcceptMutex: sysvsem 
(default: sysvsem)
[Thu Jan 07 19:37:22 2010] [error] 
/usr/lib/python2.6/site-packages/mod_python/importer.py:32: 
DeprecationWarning: the md5 module is deprecated; use hashlib instead
[Thu Jan 07 19:37:22 2010] [error]   import md5
[Thu Jan 07 19:37:38 2010] [error] 
/usr/lib/python2.6/site-packages/mod_python/importer.py:32: 
DeprecationWarning: the md5 module is deprecated; use hashlib instead
[Thu Jan 07 19:37:38 2010] [error]   import md5

On 01/07/2010 04:56 AM, Graham Dumpleton wrote:
> If you are getting a 403 forbidden error then you either haven't
> configured Apache correctly such that the mod_python URL you are using
> is a valid URL which can be accessed, that the specific URL is
> matching some pattern elsewhere in Apache which is denied for some
> reason, or, you have named your publisher handler with a leading
> underscore, which are private and therefore forbidden.
>
> You need to work out what is generating the 403, Apache or mod_python.
>
> Graham
>
> 2010/1/6 Doug Epling<depling at insightbb.com>:
>    
>> Why would I want to import apache, util?  The request object created by the
>> publisher automatically creates a FieldStorage object.  So when I pass the
>> request object, whether POST or GET, along with some other trivial data the
>> python script on the server should simply take the data argument as a
>> parameter and return a page with it printed on it.  Why doesn't the apache
>> user have this permission?
>>
>> calling page:
>>
>> def index():
>>     s = """\
>> <html>
>> <head></head>
>> <body>
>> <h2>Hello World!</h2>
>>
>> <form action="script/greet" method="GET">
>>     Name:<input type="text" name="name"><br>
>> <input type="submit">
>> </form>
>>
>> </body>
>> </html>
>> """
>>     return s
>>
>> server script:
>>
>> def greet(req, name):
>>
>>     return 'Hello %s' % name
>>
>> On 01/05/2010 09:40 PM, john burke wrote:
>>      
>>> this should be all you really need. what you do with the data from
>>> request_data is your own business.
>>>
>>> from mod_python import apache, util
>>>
>>> def login(req):
>>>
>>>    request_data = util.FieldStorage(req)
>>>
>>>    logreqdata(req, request_data)
>>>
>>>    qry = "SELECT u.user_id as id, u.user_name as name FROM users u"
>>>    qry += " WHERE u.user_name = '"
>>>    qry += request_data.getfirst("user_name")
>>>    qry += "' AND u.user_pass ='"
>>>    qry += request_data.getfirst("user_pass")
>>>    qry += "'"
>>>    return dorequest(req, qry, "users", "user").toxml("utf-8")
>>>
>>> def logreqdata(req, data):
>>>
>>>    if (DEBUG>    0):
>>>
>>>
>>> apache.log_error("********************************************************")
>>>      apache.log_error(str(req.parsed_uri))
>>>      apache.log_error(str(data))
>>>
>>> in this case you can imagine that the the dorequest method knows how to
>>> query a database (eg. some database is also imported), and that in this
>>> instance it returns xml of the form:
>>>
>>> <users>
>>> <user>
>>> <id>1</id>
>>> <name>john smith</name>
>>> </user>
>>> </users>