Re: [patch] Auth to have case sensitive username matching in DB container
| From: | Ian Eure | Date: | Thu, 13 May 2004 17:44:19 +0000 |
| Subject: | Re: [patch] Auth to have case sensitive username matching in DB container | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-29203@lists.php.net to get a copy of this message | ||
On Wednesday 12 May 2004 11:11 pm, phpWalter wrote:
> > -----Original Message-----
> > From: Ian Eure [mailto:ieure@php.net]
> > Sent: Thursday, May 13, 2004 12:43 AM
> > To: pear-dev@lists.php.net
> > Cc: Yavor Shahpasov; [php]Walter
> > Subject: Re: [PEAR-DEV] [patch] Auth to have case sensitive
> > username matching in DB container
> >
> > On Wednesday 12 May 2004 04:04 pm, Yavor Shahpasov wrote:
> > > do you mean that 'Joe' != 'joe' where joe/Joe is the
> > > username or have i completly missed the point. What
> > > is your target database.
> >
> > It appears that for some (broken?) databases, doing a SELECT
> > WHERE usernamecol = 'jOe' will match a row where usernamecol
> > = 'joe'.
>
> This is my understanding as well.
>
> Never the less, this needs to be handled.
>
> > The submitter doesn't specify what database they are using,
>
> Yes, sorry, oversight on my part... mySQL
>
What version? What type is your username column? I can't reproduce this
behavior with a simple SELECT:
mysql> select * from user where User = 'iEUre';
Empty set (0.00 sec)
mysql> select * from user where User = 'ieure';
...
2 rows in set (0.00 sec)
This is with MySQL 3.23.49. What version are you using?
> I don't follow this. "not a BC break"??
>
> What does that mean?
>
I mean that I don't think it breaks backwards compatibility. I mean, it
obviously /does/ break it, but I believe that it's correcting broken
behavior, and should be allowed. But having the username case match is, i
think, a reasonable thing to do.
Though I suspect that your problem has rather more to do with your database
than Auth itself.