Re: roles in the Pear DSN
| From: | Wolfram Kriesing | Date: | Sun, 03 Feb 2002 11:03:16 +0000 |
| Subject: | Re: roles in the Pear DSN | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4378@lists.php.net to get a copy of this message | ||
> Yes this is true. But the DSN is a thing that noone should touch,
> is a security risk to allow users to play with the DSN. Also the
> problem would only occur if you only allow users to pass their own
> special params (if they can submit any DSN they won't need to
> overwrite nothing). It's very obscure the probability of that being
> a security problem :-). Also we have no way to control the
> overwrite of the special params.For example:
i was rather thinking of something as used in tomcat
http://jakarta.apache.org/tomcat/tomcat-4.0-doc/realm-howto.html#JDBCRealm
where you can also add the parameters to the DB-url.
i was thinking of the cases, where the programmers do that.
who knows what class/application comes along and uses parseDSN for
whatever reason
--
Wolfram