Req #81023 [Opn->Nab]: Limit usable usernames or databases for MySQLi

From: Date: Mon, 31 May 2021 15:01:04 +0000
Subject: Req #81023 [Opn->Nab]: Limit usable usernames or databases for MySQLi
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234123@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81023&edit=1 ID: 81023 Updated by: bwoebi@php.net Reported by: nene at wo dot cz Summary: Limit usable usernames or databases for MySQLi -Status: Open +Status: Not a bug Type: Feature/Change Request Package: MySQLi related Operating System: Linux PHP Version: Next Major Version Block user comment: N Private report: N New Comment: PHP shall be assumed to be as powerful as any script executed as the user PHP runs under. It is trivially possible to write custom mysql drivers (with bare tcp sockets - there are libraries written in PHP for that), which would make this an ineffective bandaid. As such we are not going to support this. Previous Comments: ------------------------------------------------------------------------ [2021-05-09 16:33:54] nene at wo dot cz Or the limitation can be based on usable databases, not usernames. Both is big improvement for security. Zdenek ------------------------------------------------------------------------ [2021-05-09 16:20:04] nene at wo dot cz Description: ------------ Hello, utilizing one LAMP server for multiple webs and/or domains is quite common now. It would be great to limit the usernames which can be used to connect to MySQL database from PHP per Apache virtual and/or PHP-fpm. For example - there is one shared MySQL server for all webs. In the configuration of each web can be list of acceptable usernames to access the database. For example as php_admin_value='user1' in apache virtual. In a case that this virtual invoke in PHP mysqli_connect with different username than 'user1', this will be prohibited. This can improve the security of shared web server services, because one web cannot make brute force password attack to databases of other webs. BR, Zdenek ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81023&edit=1

« previous php.bugs (#234123) next »