Is it ever ok to store password in plain text in a php variable or php constant?

后端 未结 8 2335
借酒劲吻你
借酒劲吻你 2020-11-27 18:58

As per question, is it safe to store passwords on php pages such as

$password = \'pa$$w0rd\';

If the users can\'t see it, it\'s safe, right

8条回答
  •  南笙
    南笙 (楼主)
    2020-11-27 19:33

    It depends how you define 'safe'.

    You are right in that a general user won't see it.

    However it is definitely a bad practice; if your site is compromised, what else will these passwords give access to? I'd say at a bare minimum you should be storing a hash of the password, not the plaintext.

提交回复
热议问题