note 53559 added to ref.pgsql
| From: | anis_wn at gawab dot com | Date: | Mon, 06 Jun 2005 04:45:19 +0000 |
| Subject: | note 53559 added to ref.pgsql | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-89984@lists.php.net to get a copy of this message | ||
Setting up PostgreSQL for higher security PHP connection.
Case:
We want to connect to PostgreSQL database using username and password supplied by webuser at login
time.
Fact (Linux):
Apache (perhaps other servers, too) running the server as (default to) apache user account. So if
you connect to PostgreSQL using default user, apache will be assingned for it. If you hard code the
user and password in your PHP script, you'll loose security restriction from PostgreSQL.
Solution:
(You are assumed to have enough privilege to do these things, though)
1. Edit pg_hba.conf to have the line like the one below
host db_Name [web_server_ip_address] [ip_address_mask] md5
2. Add to you script the login page that submits username and password.
3. Use those information to login to PostgreSQL like these...
<?
$conn = "host=$DBHost port=$DBPort dbname=$DBName ".
"user='{$_POST['dbUsername']}'
password='{$_POST['dbPassword']}'";
$db = pg_connect ($conn);
[your other codes go here...]
?>
4. You must add users in PostgreSQL properly.
5. For your convenience, you can store the username and password to $_SESSION variable.
Good luck.
Anis WN
----
Manual Page -- http://www.php.net/manual/en/ref.pgsql.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+53559
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+53559&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+53559&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+53559&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+53559&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+53559&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+53559&report=yes
Search -- http://master.php.net/manage/user-notes.php