note 53559 added to ref.pgsql

From: Date: Mon, 06 Jun 2005 04:45:19 +0000
Subject: note 53559 added to ref.pgsql
Groups: php.notes 
Request: Send a blank email to php-notes+get-89984@lists.php.net to get a copy of this message
Setting up PostgreSQL for higher security PHP connection. Case: We want to connect to PostgreSQL database using username and password supplied by webuser at login time. Fact (Linux): Apache (perhaps other servers, too) running the server as (default to) apache user account. So if you connect to PostgreSQL using default user, apache will be assingned for it. If you hard code the user and password in your PHP script, you'll loose security restriction from PostgreSQL. Solution: (You are assumed to have enough privilege to do these things, though) 1. Edit pg_hba.conf to have the line like the one below host db_Name [web_server_ip_address] [ip_address_mask] md5 2. Add to you script the login page that submits username and password. 3. Use those information to login to PostgreSQL like these... <? $conn = "host=$DBHost port=$DBPort dbname=$DBName ". "user='{$_POST['dbUsername']}' password='{$_POST['dbPassword']}'"; $db = pg_connect ($conn); [your other codes go here...] ?> 4. You must add users in PostgreSQL properly. 5. For your convenience, you can store the username and password to $_SESSION variable. Good luck. Anis WN ---- Manual Page -- http://www.php.net/manual/en/ref.pgsql.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+53559 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+53559&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+53559&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+53559&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+53559&report=yes&reason=useless Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+53559&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+53559&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#89984) next »