Re: roles in the Pear DSN

From: Date: Sun, 03 Feb 2002 11:03:16 +0000
Subject: Re: roles in the Pear DSN
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4378@lists.php.net to get a copy of this message
> Yes this is true. But the DSN is a thing that noone should touch, > is a security risk to allow users to play with the DSN. Also the > problem would only occur if you only allow users to pass their own > special params (if they can submit any DSN they won't need to > overwrite nothing). It's very obscure the probability of that being > a security problem :-). Also we have no way to control the > overwrite of the special params.For example: i was rather thinking of something as used in tomcat http://jakarta.apache.org/tomcat/tomcat-4.0-doc/realm-howto.html#JDBCRealm where you can also add the parameters to the DB-url. i was thinking of the cases, where the programmers do that. who knows what class/application comes along and uses parseDSN for whatever reason -- Wolfram

« previous php.pear.dev (#4378) next »