RE: [PHP] .co.uk Site Hosting.

From: Date: Fri, 18 Aug 2000 10:35:03 +0000
Subject: RE: [PHP] .co.uk Site Hosting.
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-12457@lists.php.net to get a copy of this message
Hiya, : - MySQL with full admin access (the ability to set up user accounts). I'm : going to be creating accounts to do a very specific task, while : the username : & passwords from .htpasswd will be used to allow major write : changes to the : database. These will be obtained from $PHP_AUTH_USER and $PHP_AUTH_PW. Thank you for the response. I'm slowly making my way though them and making notes. I'll probably send of a few e-mails and questions to the various companies today. Having heard what you said, and the problems being faced, do you think that this is the wrong way of going about things? I've got a small web site, displaying about 200 properties for sale or for rent, and covers much of the property currently being dealt by my client. Although a dedicated server would be nice (even just for myself), neither I nor my client can really afford one. A virtual server is the best course of action. With all the problems currently being faced with security and hackers invaded (and this really being my first full PHP/MySQL site), I wanted to try and instigate a few security features, with an attempt to try and combat the problem, should the site need to expand further. The main idea was to use a series of username and password combinations to do specific tasks on tables and databases. For example, one account would only be allows to write to the kjtoombs.stats table, while another could only SELECT data relating to staff members. That way, no one account, written in PHP script would contain access accounts that could do damage to the database. To then make changes to the database, Apache, using .htpasswd and .htaccess files under a secure directory would require the client or myself to enter a username and password, which would then be available to PHP, using mod_php, via $PHP_AUTH_PW and $PHP_AUTH_USER. These then could access the account, but in only a way as to update and adjust what they needed. That was, the passwords are secure with Apache, and not available to anyone on the outside. Is this a wrong way about doing things then? Is just a 'root' account, or an account to just adjust your database normal throughout a script? Is that now the best way to proceed? I haven't really started on the programming. I've just finished the underlying classes and functions required to interact with the database and print out standard sections of HTML code, adjusted to what's required. Thanks for your help. - - - - - - - - - - - - - - - - - - - - Jonathan Wright [DjNA] mail@djna.fsnet.co.uk www.djna.fsnet.co.uk ICQ [21961373]

« previous php.general (#12457) next »