note 116010 deleted from pdo.connections by salathe
| From: | salathe@php.net | Date: | Fri, 07 Nov 2014 10:59:38 +0000 |
| Subject: | note 116010 deleted from pdo.connections by salathe | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-200809@lists.php.net to get a copy of this message | ||
Note Submitter: Anonymous
----
"If your application does not catch the exception thrown from the PDO constructor, the default
action taken by the zend engine is to terminate the script and display a back trace. This back trace
will likely reveal the full database connection details, including the username and password. It is
your responsibility to catch this exception"
Never should any error message reveal usernames and passwords - especially should it not be default
behavior of PHP. About time to remove the absurdity of php errors off, but PDO connection singing
out loud credentials to the World if database is down. Try-catch should not be required to preserve
basic security.