Req #81023 [Opn]: Limit usable usernames or databases for MySQLi
| From: | nene at wo dot cz | Date: | Sun, 09 May 2021 16:33:54 +0000 |
| Subject: | Req #81023 [Opn]: Limit usable usernames or databases for MySQLi | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233754@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81023&edit=1
ID: 81023
User updated by: nene at wo dot cz
Reported by: nene at wo dot cz
-Summary: Limit usable usernames for MySQLi
+Summary: Limit usable usernames or databases for MySQLi
Status: Open
Type: Feature/Change Request
Package: MySQLi related
Operating System: Linux
PHP Version: Next Major Version
Block user comment: N
Private report: N
New Comment:
Or the limitation can be based on usable databases, not usernames. Both is big improvement for
security.
Zdenek
Previous Comments:
------------------------------------------------------------------------
[2021-05-09 16:20:04] nene at wo dot cz
Description:
------------
Hello,
utilizing one LAMP server for multiple webs and/or domains is quite common now. It would be great to
limit the usernames which can be used to connect to MySQL database from PHP per Apache virtual
and/or PHP-fpm.
For example - there is one shared MySQL server for all webs. In the configuration of each web can be
list of acceptable usernames to access the database. For example as
php_admin_value='user1' in apache virtual. In a case that this virtual invoke in PHP
mysqli_connect with different username than 'user1', this will be prohibited.
This can improve the security of shared web server services, because one web cannot make brute force
password attack to databases of other webs.
BR,
Zdenek
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81023&edit=1