note 116010 added to pdo.connections
| From: | Anonymous | Date: | Wed, 29 Oct 2014 09:08:31 +0000 |
| Subject: | note 116010 added to pdo.connections | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-200742@lists.php.net to get a copy of this message | ||
"If your application does not catch the exception thrown from the PDO constructor, the default
action taken by the zend engine is to terminate the script and display a back trace. This back trace
will likely reveal the full database connection details, including the username and password. It is
your responsibility to catch this exception"
Never should any error message reveal usernames and passwords - especially should it not be default
behavior of PHP. About time to remove the absurdity of php errors off, but PDO connection singing
out loud credentials to the World if database is down. Try-catch should not be required to preserve
basic security.
----
Server IP: 217.146.68.100
Probable Submitter: 90.190.191.162
----
Manual Page -- http://php.net/manual/en/pdo.connections.php
Edit -- https://master.php.net/note/edit/116010
Del: integrated -- https://master.php.net/note/delete/116010/integrated
Del: useless -- https://master.php.net/note/delete/116010/useless
Del: bad code -- https://master.php.net/note/delete/116010/bad+code
Del: spam -- https://master.php.net/note/delete/116010/spam
Del: non-english -- https://master.php.net/note/delete/116010/non-english
Del: in docs -- https://master.php.net/note/delete/116010/in+docs
Del: other reasons-- https://master.php.net/note/delete/116010
Reject -- https://master.php.net/note/reject/116010
Search -- https://master.php.net/manage/user-notes.php