note 49206 added to security.database.storage
| From: | arnodotesterhuizenatgmaildotcom at osu1 dot php dot net | Date: | Thu, 20 Jan 2005 07:11:16 +0000 |
| Subject: | note 49206 added to security.database.storage | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-83652@lists.php.net to get a copy of this message | ||
In the code cited in the manual, wouldn't it be more secure to say
if (pg_num_rows($result) == 1) {
echo 'Welcome, $username!';
} else {
echo 'Authentication failed for $username.';
}
This way the code checks for only one valid user. Or is this needlessly pedantic? Let me know.
Arno
----
Manual Page -- http://www.php.net/manual/en/security.database.storage.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+49206
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+49206&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+49206&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+49206&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+49206&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+49206&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+49206&report=yes
Search -- http://master.php.net/manage/user-notes.php