is it safe to store username and password for mysql connection in session variables?
| From: | anders thoresson | Date: | Sun, 23 Nov 2003 14:54:41 +0000 |
| Subject: | is it safe to store username and password for mysql connection in session variables? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-170717@lists.php.net to get a copy of this message | ||
Hi,
In the ini-files for my php-projects, I store various settings. Two of them is username and password for my mysql-connections.
Is it safe to load these two into session variables when a user logs in to my application? Or is it better to access the ini-file each time a mysql-connection is needed?
What I don't understand, and hence the questions, is wether session variables are accessible by my website's visitors, or just to the php-scripts on the server.
--
anders thoresson