RE: [PHP] .co.uk Site Hosting.
| From: | Jonathan Wright \(DjNA\) | Date: | Fri, 18 Aug 2000 10:35:03 +0000 |
| Subject: | RE: [PHP] .co.uk Site Hosting. | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12457@lists.php.net to get a copy of this message | ||
Hiya,
: - MySQL with full admin access (the ability to set up user accounts). I'm
: going to be creating accounts to do a very specific task, while
: the username
: & passwords from .htpasswd will be used to allow major write
: changes to the
: database. These will be obtained from $PHP_AUTH_USER and $PHP_AUTH_PW.
Thank you for the response. I'm slowly making my way though them and making
notes. I'll probably send of a few e-mails and questions to the various
companies today.
Having heard what you said, and the problems being faced, do you think that
this is the wrong way of going about things?
I've got a small web site, displaying about 200 properties for sale or for
rent, and covers much of the property currently being dealt by my client.
Although a dedicated server would be nice (even just for myself), neither I
nor my client can really afford one. A virtual server is the best course of
action.
With all the problems currently being faced with security and hackers
invaded (and this really being my first full PHP/MySQL site), I wanted to
try and instigate a few security features, with an attempt to try and combat
the problem, should the site need to expand further.
The main idea was to use a series of username and password combinations to
do specific tasks on tables and databases. For example, one account would
only be allows to write to the kjtoombs.stats table, while another could
only SELECT data relating to staff members. That way, no one account,
written in PHP script would contain access accounts that could do damage to
the database.
To then make changes to the database, Apache, using .htpasswd and .htaccess
files under a secure directory would require the client or myself to enter a
username and password, which would then be available to PHP, using mod_php,
via $PHP_AUTH_PW and $PHP_AUTH_USER. These then could access the account,
but in only a way as to update and adjust what they needed. That was, the
passwords are secure with Apache, and not available to anyone on the
outside.
Is this a wrong way about doing things then? Is just a 'root' account, or an
account to just adjust your database normal throughout a script? Is that now
the best way to proceed? I haven't really started on the programming. I've
just finished the underlying classes and functions required to interact with
the database and print out standard sections of HTML code, adjusted to
what's required.
Thanks for your help.
- - - - - - - - - - - - - - - - - - - -
Jonathan Wright [DjNA]
mail@djna.fsnet.co.uk
www.djna.fsnet.co.uk
ICQ [21961373]