PHP 4.0 Bug #6198 Updated: Connecting to Postgres backend

From: Date: Fri, 03 Nov 2000 04:45:53 +0000
Subject: PHP 4.0 Bug #6198 Updated: Connecting to Postgres backend
Groups: php.dev 
Request: Send a blank email to php-dev+get-36905@lists.php.net to get a copy of this message
ID: 6198 Updated by: ronabop Reported By: goran@cenis.org.yu Status: Assigned Bug Type: Documentation problem Assigned To: jah Comments: New syntax has been documented. Previous Comments: --------------------------------------------------------------------------- [2000-08-23 19:15:25] jah@php.net Writing pg_connect() the way it would work with both older and newer versions of PostgreSQL seems a bit unnecessary work, because the same time PQsetdbLogin() replaced PQsetdb() in PostgreSQL APIs, there came also a new function PQconnectdb(), that takes one argument, a connection argument string. That's the current preferred way, because using it, the calling application doesn't actually have to now anything about the possible parameters, and they can be changed or there can be additions at the will of PostgreSQL developer team. PHP manual just notes that pg_connect() can be called this way too, not that the old way this is deprecated. This should/will be fixed in the manual. -- Jouni PS. Jani, hieno juttu että joku tosiaan jaksaa käydä näitä bugeja läpi, mutta ihan kaikkeen ei ehkä pidä koskea tietämättä täsmälleen mistä on kyse.... No, olihan tää multakin kyllä fixaamatta. --------------------------------------------------------------------------- [2000-08-23 08:59:48] sniper@php.net Reclassified. --Jani --------------------------------------------------------------------------- [2000-08-16 12:51:23] goran@cenis.org.yu Functions pg_connect() and pg_pconnect() always connect to the PostgreSQL database with the user ID of the httpd server process. There is no way to set the user ID from PHP script, although Postgres connection protocol allows setting of username and password. This raises some security issues, because granting of access rights for database objects can't be properly imposed (user that httpd runs as has to have all rights to all database objects which PHP script must access). In the libpq library there are two database connection functions: PQsetdb() and PQsetdbLogin() with prototypes as: PGconn *PQsetdbLogin(const char *pghost, const char *pgport, const char *pgoptions, const char *pgtty, const char *dbName, const char *login, const char *pwd) PGconn *PQsetdb(char *pghost, char *pgport, char *pgoptions, char *pgtty, char *dbName) The Postgres programming manual states that PQsetdb() is only a macro that calls PQsetdbLogin() with null pointers for the login and pwd parameters, and that it is provided primarily for backward compatibility with old programs!!! I looked up pgsql.c module a little bit, and I noticed that it still uses old PQsetdb() function, which not only might soon be obsolete, but does not allow for user and password for database connection to be set programmatically. I think that this issue should be addressed as soon as possible. I would do it myself, but I'm not that comfortable with C/C++ programming. --------------------------------------------------------------------------- Full Bug description available at: http://bugs.php.net/?id=6198

« previous php.dev (#36905) next »