RE: [PEAR-DEV] MySql connect / broken?
| From: | richard quinn | Date: | Mon, 15 Sep 2003 19:23:56 +0000 |
| Subject: | RE: [PEAR-DEV] MySql connect / broken? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-21520@lists.php.net to get a copy of this message | ||
OK, a quick dig around in the mysql docu shows:
<docu>
MYSQL *mysql_real_connect(MYSQL *mysql, const char *host, const char
*user, const char *passwd, const char *db, unsigned int port, const char
*unix_socket, unsigned long client_flag)
<snip />
http://www.mysql.com/doc/en/mysql_real_connect.html
The passwd parameter contains the password for user. If passwd is NULL,
only entries in the user table for the user that have a blank (empty)
password field will be checked for a match. This allows the database
administrator to set up the MySQL privilege system in such a way that
users get different privileges depending on whether or not they have
specified a password. Note: Do not attempt to encrypt the password
before calling mysql_real_connect(); password encryption is handled
automatically by the client API.
</docu>
So, the PEAR code will give a NULL into the mysql_real_connect function
if the $pw parameter is empty, which will cause it to entirely paas the
root user by if that password is set to "<zero length string>".
This applies to version 4.x MySQL, I run version 4.0.15.
The PEAR connect is broken, it will not correctly connect to MySQL -
where the password has been set to a zero length string - unless changed
as I propose here.
- Richard
> -----Original Message-----
> From: Robin Ericsson [mailto:robin.ericsson@profecta.se]
> Sent: Monday, September 15, 2003 2:37 PM
> To: pear-dev@lists.php.net
> Subject: Re: [PEAR-DEV] MySql connect / broken?
>
>
> On Mon, 2003-09-15 at 13:11, richard quinn wrote:
> > Hi,
> >
> > I have had a 3 year break from PHP, but have just started up again.
> > Of course the first task was to get PEAR working, it seems a big
> > improvement over PHP-Lib.
> >
> > Except:
> > My default MySQL installation is root / <empty password>, but the
> > MYSQL::Connect can't cope with this. In particular, from
> lines 122 in
> > mysql.php:
> >
> > if ($dbhost && $user && $pw) {
> > $conn = @$connect_function($dbhost, $user, $pw);
> > } elseif ($dbhost && $user) {
> > $conn = @$connect_function($dbhost, $user);
> > } elseif ($dbhost) {
> > $conn = @$connect_function($dbhost);
> > } else {
> > $conn = false;
> > }
> >
> > So I connect with
> > $dbhost = 'localhost';
> > $user = root;
> > $pass = '';
> >
> > The code above goes to the first else condition:
> >
> > $conn = @$connect_function($dbhost, $user);
> >
> > And Mysql returns an error saying that the password is
> incorrect, since
> > it should be ''.
> > My quickfix:
> >
> > if ($dbhost && $user && $pw) {
> > $conn = @$connect_function($dbhost, $user, $pw);
> > } elseif ($dbhost && $user) {
> > $conn = @$connect_function($dbhost, $user, $pw);
> > if (empty($conn)) {
> > $conn = @$connect_function($dbhost, $user);
> > }
> > } elseif ($dbhost) {
> > $conn = @$connect_function($dbhost);
> > } else {
> > $conn = false;
> > }
> >
> > Seems to fix the problem. If no $pw is empty, I still try to connect
> > with it. If it doesn't work: i.e. MySQL does not want to
> see an empty
> > password, then we just try again. But an improvement over
> the current
> > DSN parsing schema would surely be to add a connection_info class?
> > Attributes: user, pw, host, db. The ::connect functions
> could recieve
> > the connection_info class and be informed whether a value
> is nonexistent
> > or set to an empty string...
> >
> > Just some thoughts, I hope I chose the correct list here..
>
> You should direct this question to pear-general really, as this is a
> problem on your side :)
>
> Using dsn there is no problem connecting to mysql without
> password like
> this:
>
> mysql://root@localhost/database
>
>
> hth
> Robin
>
> --
> PEAR Development Mailing List (http://pear.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>