PHP 4.0 Bug #6198 Updated: Connecting to Postgres backend
| From: | ronabop@php.net | Date: | Fri, 03 Nov 2000 04:45:53 +0000 |
| Subject: | PHP 4.0 Bug #6198 Updated: Connecting to Postgres backend | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-36905@lists.php.net to get a copy of this message | ||
ID: 6198
Updated by: ronabop
Reported By: goran@cenis.org.yu
Status: Assigned
Bug Type: Documentation problem
Assigned To: jah
Comments:
New syntax has been documented.
Previous Comments:
---------------------------------------------------------------------------
[2000-08-23 19:15:25] jah@php.net
Writing pg_connect() the way it would work with both older and newer versions of
PostgreSQL seems a bit unnecessary work, because the same time PQsetdbLogin()
replaced PQsetdb() in PostgreSQL APIs, there came also a new function PQconnectdb(), that takes one
argument, a connection argument string. That's the current preferred way, because using it, the
calling application doesn't actually have to now anything about the possible parameters, and
they can be changed or there can be additions at the will of PostgreSQL developer team. PHP manual
just notes that pg_connect() can be called this way too, not that the old way this is deprecated.
This should/will be fixed in the manual.
-- Jouni
PS. Jani, hieno juttu että joku tosiaan jaksaa käydä näitä bugeja läpi, mutta ihan kaikkeen ei
ehkä pidä koskea tietämättä täsmälleen mistä on kyse.... No, olihan tää multakin kyllä
fixaamatta.
---------------------------------------------------------------------------
[2000-08-23 08:59:48] sniper@php.net
Reclassified.
--Jani
---------------------------------------------------------------------------
[2000-08-16 12:51:23] goran@cenis.org.yu
Functions pg_connect() and pg_pconnect() always connect to the PostgreSQL database with the user ID
of the httpd server process. There is no way to set the user ID from PHP script, although Postgres
connection protocol allows setting of username and password.
This raises some security issues, because granting of access rights for database objects can't
be properly imposed (user that httpd runs as has to have all rights to all database objects which
PHP script must access).
In the libpq library there are two database connection functions: PQsetdb() and PQsetdbLogin() with
prototypes as:
PGconn *PQsetdbLogin(const char *pghost,
const char *pgport,
const char *pgoptions,
const char *pgtty,
const char *dbName,
const char *login,
const char *pwd)
PGconn *PQsetdb(char *pghost,
char *pgport,
char *pgoptions,
char *pgtty,
char *dbName)
The Postgres programming manual states that PQsetdb() is only a macro that calls PQsetdbLogin() with
null pointers for the login and pwd parameters, and that it is provided primarily for backward
compatibility with old programs!!!
I looked up pgsql.c module a little bit, and I noticed that it still uses old PQsetdb() function,
which not only might soon be obsolete, but does not allow for user and password for database
connection to be set programmatically.
I think that this issue should be addressed as soon as possible. I would do it myself, but I'm
not that comfortable with C/C++ programming.
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=6198