Re: is it safe to store username and password for mysql connection in session variables?
| From: | Comex | Date: | Sun, 23 Nov 2003 15:37:13 +0000 |
| Subject: | Re: is it safe to store username and password for mysql connection in session variables? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-170719@lists.php.net to get a copy of this message | ||
<opry3idfmizzwwoi@mail.darkface.pp.se>
Anders Thoresson:
> Hi,
>
> In the ini-files for my php-projects, I store various settings. Two
> of them is username and password for my mysql-connections.
>
> Is it safe to load these two into session variables when a user
> logs in to my application? Or is it better to access the ini-file
> each time a mysql-connection is needed?
>
> What I don't understand, and hence the questions, is wether session
> variables are accessible by my website's visitors, or just to the
> php-scripts on the server.
AFAIK only to the scripts. But then again it's always good to be secure.
Read the ini file.
--
Comex