Re: cvs: /php3 ChangeLog

From: Date: Thu, 01 Jan 1970 00:00:00 +0000
Subject: Re: cvs: /php3 ChangeLog
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-13071@lists.php.net to get a copy of this message
> > No, you didn't miss anything. Some bugs popped up and I have been slow in > > addressing them. The main thing left at this point is that the > > mysql_change_user() function needs to modify the hashed information for > > the persistent connection it modifies. > > This could be easily solved, if the MySQL module would not be > affected by a bad design decision which has been made for > many other modules as well. > > The MySQL module only stores the database handle in the list. > This is convenient for most functions; the ugly side of it is > that you loose all meta information associated with the > database connection. > > If this information (host, username, password) would be > stored in the list as well, the required information to > update the persistent list (in this case) would be readily > available. > > As a workaround, a new hash table should be added which maps > connection handles to meta information, so that meta > information can be easily looked up. This increases the > overhead of maintaining connections, but is the prerequisite > for performing the action Rasmus described. Yeah, I know. That's what I have been looking at doing, but it isn't a 10-minute hack. I need to set aside a couple of hours to make sure it is done right. However, I am starting to think that we shouldn't do this in PHP 3 and as such I think mysql_change_user() should be yanked from the 3.0 code, or limited to work on non-persistent connections only. If we let people change the logged in user on a persistent connection without modifying the hashed details we have a security issue. -Rasmus

« previous php.dev (#13071) next »