RE: [PEAR-DEV] MySql connect / broken?

From: Date: Mon, 15 Sep 2003 19:23:56 +0000
Subject: RE: [PEAR-DEV] MySql connect / broken?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-21520@lists.php.net to get a copy of this message
OK, a quick dig around in the mysql docu shows: <docu> MYSQL *mysql_real_connect(MYSQL *mysql, const char *host, const char *user, const char *passwd, const char *db, unsigned int port, const char *unix_socket, unsigned long client_flag) <snip /> http://www.mysql.com/doc/en/mysql_real_connect.html The passwd parameter contains the password for user. If passwd is NULL, only entries in the user table for the user that have a blank (empty) password field will be checked for a match. This allows the database administrator to set up the MySQL privilege system in such a way that users get different privileges depending on whether or not they have specified a password. Note: Do not attempt to encrypt the password before calling mysql_real_connect(); password encryption is handled automatically by the client API. </docu> So, the PEAR code will give a NULL into the mysql_real_connect function if the $pw parameter is empty, which will cause it to entirely paas the root user by if that password is set to "<zero length string>". This applies to version 4.x MySQL, I run version 4.0.15. The PEAR connect is broken, it will not correctly connect to MySQL - where the password has been set to a zero length string - unless changed as I propose here. - Richard > -----Original Message----- > From: Robin Ericsson [mailto:robin.ericsson@profecta.se] > Sent: Monday, September 15, 2003 2:37 PM > To: pear-dev@lists.php.net > Subject: Re: [PEAR-DEV] MySql connect / broken? > > > On Mon, 2003-09-15 at 13:11, richard quinn wrote: > > Hi, > > > > I have had a 3 year break from PHP, but have just started up again. > > Of course the first task was to get PEAR working, it seems a big > > improvement over PHP-Lib. > > > > Except: > > My default MySQL installation is root / <empty password>, but the > > MYSQL::Connect can't cope with this. In particular, from > lines 122 in > > mysql.php: > > > > if ($dbhost && $user && $pw) { > > $conn = @$connect_function($dbhost, $user, $pw); > > } elseif ($dbhost && $user) { > > $conn = @$connect_function($dbhost, $user); > > } elseif ($dbhost) { > > $conn = @$connect_function($dbhost); > > } else { > > $conn = false; > > } > > > > So I connect with > > $dbhost = 'localhost'; > > $user = root; > > $pass = ''; > > > > The code above goes to the first else condition: > > > > $conn = @$connect_function($dbhost, $user); > > > > And Mysql returns an error saying that the password is > incorrect, since > > it should be ''. > > My quickfix: > > > > if ($dbhost && $user && $pw) { > > $conn = @$connect_function($dbhost, $user, $pw); > > } elseif ($dbhost && $user) { > > $conn = @$connect_function($dbhost, $user, $pw); > > if (empty($conn)) { > > $conn = @$connect_function($dbhost, $user); > > } > > } elseif ($dbhost) { > > $conn = @$connect_function($dbhost); > > } else { > > $conn = false; > > } > > > > Seems to fix the problem. If no $pw is empty, I still try to connect > > with it. If it doesn't work: i.e. MySQL does not want to > see an empty > > password, then we just try again. But an improvement over > the current > > DSN parsing schema would surely be to add a connection_info class? > > Attributes: user, pw, host, db. The ::connect functions > could recieve > > the connection_info class and be informed whether a value > is nonexistent > > or set to an empty string... > > > > Just some thoughts, I hope I chose the correct list here.. > > You should direct this question to pear-general really, as this is a > problem on your side :) > > Using dsn there is no problem connecting to mysql without > password like > this: > > mysql://root@localhost/database > > > hth > Robin > > -- > PEAR Development Mailing List (http://pear.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php >

« previous php.pear.dev (#21520) next »