Req #81023 [Opn->Nab]: Limit usable usernames or databases for MySQLi
| From: | bwoebi@php.net | Date: | Mon, 31 May 2021 15:01:04 +0000 |
| Subject: | Req #81023 [Opn->Nab]: Limit usable usernames or databases for MySQLi | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234123@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81023&edit=1
ID: 81023
Updated by: bwoebi@php.net
Reported by: nene at wo dot cz
Summary: Limit usable usernames or databases for MySQLi
-Status: Open
+Status: Not a bug
Type: Feature/Change Request
Package: MySQLi related
Operating System: Linux
PHP Version: Next Major Version
Block user comment: N
Private report: N
New Comment:
PHP shall be assumed to be as powerful as any script executed as the user PHP runs under.
It is trivially possible to write custom mysql drivers (with bare tcp sockets - there are libraries
written in PHP for that), which would make this an ineffective bandaid. As such we are not going to
support this.
Previous Comments:
------------------------------------------------------------------------
[2021-05-09 16:33:54] nene at wo dot cz
Or the limitation can be based on usable databases, not usernames. Both is big improvement for
security.
Zdenek
------------------------------------------------------------------------
[2021-05-09 16:20:04] nene at wo dot cz
Description:
------------
Hello,
utilizing one LAMP server for multiple webs and/or domains is quite common now. It would be great to
limit the usernames which can be used to connect to MySQL database from PHP per Apache virtual
and/or PHP-fpm.
For example - there is one shared MySQL server for all webs. In the configuration of each web can be
list of acceptable usernames to access the database. For example as
php_admin_value='user1' in apache virtual. In a case that this virtual invoke in PHP
mysqli_connect with different username than 'user1', this will be prohibited.
This can improve the security of shared web server services, because one web cannot make brute force
password attack to databases of other webs.
BR,
Zdenek
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81023&edit=1