Re: roles in the Pear DSN

From: Date: Fri, 01 Feb 2002 16:43:28 +0000
Subject: Re: roles in the Pear DSN
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4331@lists.php.net to get a copy of this message
El vie, 01-02-2002 a las 17:17, Wolfram Kriesing escribió: > > > the way you have done it, you need to be sure to never use a > > > parameter-name which is already a key in the dsn array, is that > > > not dangerous?? > > > > Why? > > if i pass a url like > db-type://user1:myPassword@localhost/dbname?username=x&password=y > > then it would overwrite the already set values "user1:myPassword" > with "x:y" > or am i mistaken? or is it sure that this will never be the case? > Yes this is true. But the DSN is a thing that noone should touch, is a security risk to allow users to play with the DSN. Also the problem would only occur if you only allow users to pass their own special params (if they can submit any DSN they won't need to overwrite nothing). It's very obscure the probability of that being a security problem :-). Also we have no way to control the overwrite of the special params.For example: ibase://user@localhost/foo and the malicious user submits a: ibase://user@localhost/foo?role=low Any way, as I don't find any reason why support the overwrite of: 'phptype' 'dbsyntax' 'username' 'password' 'protocol' 'hostspec' 'port' 'socket' 'database' I'll introduce a test before the assign. Well, I actually did it :-). Thanks. Tomas V.V.Cox

« previous php.pear.dev (#4331) next »