note 116010 added to pdo.connections

From: Date: Wed, 29 Oct 2014 09:08:31 +0000
Subject: note 116010 added to pdo.connections
Groups: php.notes 
Request: Send a blank email to php-notes+get-200742@lists.php.net to get a copy of this message
"If your application does not catch the exception thrown from the PDO constructor, the default action taken by the zend engine is to terminate the script and display a back trace. This back trace will likely reveal the full database connection details, including the username and password. It is your responsibility to catch this exception" Never should any error message reveal usernames and passwords - especially should it not be default behavior of PHP. About time to remove the absurdity of php errors off, but PDO connection singing out loud credentials to the World if database is down. Try-catch should not be required to preserve basic security. ---- Server IP: 217.146.68.100 Probable Submitter: 90.190.191.162 ---- Manual Page -- http://php.net/manual/en/pdo.connections.php Edit -- https://master.php.net/note/edit/116010 Del: integrated -- https://master.php.net/note/delete/116010/integrated Del: useless -- https://master.php.net/note/delete/116010/useless Del: bad code -- https://master.php.net/note/delete/116010/bad+code Del: spam -- https://master.php.net/note/delete/116010/spam Del: non-english -- https://master.php.net/note/delete/116010/non-english Del: in docs -- https://master.php.net/note/delete/116010/in+docs Del: other reasons-- https://master.php.net/note/delete/116010 Reject -- https://master.php.net/note/reject/116010 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#200742) next »