Bug #14564 Updated: Trusted Connections Not Supported
| From: | derick@php.net | Date: | Mon, 17 Dec 2001 16:27:14 +0000 |
| Subject: | Bug #14564 Updated: Trusted Connections Not Supported | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-74163@lists.php.net to get a copy of this message | ||
ID: 14564
Updated by: derick
Reported By: parkins.graham@ppc-consulting.co.uk
Status: Open
Old Bug Type: MSSQL related
Bug Type: Feature/Change Request
Operating System: Windows NT 4/SQL Server 7
PHP Version: 4.1.0
New Comment:
Making this a feature request
Previous Comments:
------------------------------------------------------------------------
[2001-12-17 11:12:07] parkins.graham@ppc-consulting.co.uk
I consider the inclusion of database usernames and passwords in scripts to be a security risk.
In a Windows environment it is possible to access SQL Server via a trusted connection. This uses
the context of the current logged in user.
Furthermore it is possible to configure IIS and presumably Apache to use a particular user account
to service requests.
It is therefore possible (for example under ASP) to open a database connection without specifying a
username or password in the script because the context of the current user account has permission to
access the SQL Server.
I would be happy if this functionality could be implmented in the MS SQL Server extension.
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=14564&edit=1