Re: roles in the Pear DSN
| From: | Tomas V.V.Cox | Date: | Fri, 01 Feb 2002 16:43:28 +0000 |
| Subject: | Re: roles in the Pear DSN | ||
| References: | 1 2 3 4 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4331@lists.php.net to get a copy of this message | ||
El vie, 01-02-2002 a las 17:17, Wolfram Kriesing escribió:
> > > the way you have done it, you need to be sure to never use a
> > > parameter-name which is already a key in the dsn array, is that
> > > not dangerous??
> >
> > Why?
>
> if i pass a url like
> db-type://user1:myPassword@localhost/dbname?username=x&password=y
>
> then it would overwrite the already set values "user1:myPassword"
> with "x:y"
> or am i mistaken? or is it sure that this will never be the case?
>
Yes this is true. But the DSN is a thing that noone should touch, is a
security risk to allow users to play with the DSN. Also the problem
would only occur if you only allow users to pass their own special
params (if they can submit any DSN they won't need to overwrite
nothing). It's very obscure the probability of that being a security
problem :-). Also we have no way to control the overwrite of the special
params.For example:
ibase://user@localhost/foo
and the malicious user submits a:
ibase://user@localhost/foo?role=low
Any way, as I don't find any reason why support the overwrite of:
'phptype'
'dbsyntax'
'username'
'password'
'protocol'
'hostspec'
'port'
'socket'
'database'
I'll introduce a test before the assign. Well, I actually did it :-).
Thanks.
Tomas V.V.Cox