Re: Proposal: Establish DB connections during module_init

From: Date: Wed, 07 Jun 2000 22:25:33 +0000
Subject: Re: Proposal: Establish DB connections during module_init
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-20519@lists.php.net to get a copy of this message
On 7 Jun 2000, Manuel Lemos wrote: > ><VirtualHost www.php.net> > > php_admin_value mysql.default_host=localhost > > php_admin_value mysql.default_user=rasmus > > php_admin_value mysql.default_password=foobar > > php_admin_value mysql.autoconnect=On > > ... > ></VirtualHost> > > OTOH, I don't know if developers will want to have their database passwords > in clear text scattered for more places that it should. Some people use > databases to protect the content of their sites. Having passwords in the Apache > configuration makes it easier for that protection be defeated. It would be > better (not absolutely safe though) to have database password defined in > PHP code where the user thinks its best. I'd say httpd.conf is a lot of safer place to put cleartext passwords than anywhere in PHP code. Apache usually starts as root privileges, reads httpd.conf, starts forking children, and only the children change their uid/gid to something unprivileged. So, httpd.conf can have the privileges 0700 and be owned by root, unlike PHP code... In fact, even the users themselves don't need to know their username and password to access the database, because it can be assigned by sysadm per virtualhost/directory. An idea: a possible extension to SQL safe mode could be that the values assigned by sysadm can't be overridden anyway or even seen by ini_get(). Could make some sysadmins happy. -- Jouni Ahto

« previous php.dev (#20519) next »