PDO Connect with an encrypted password?

前端 未结 2 952
野的像风
野的像风 2021-01-26 05:37

Ideally I would prefer not to have a password for a database in its raw form in a config file.

Is there away that pdo mysql connect accepts a md5 or sha1 version??

2条回答
  •  长发绾君心
    2021-01-26 06:34

    1) make the file only accessible to www-data.

    2) never use a username/pw combo that has more privelage than needed (eg no grant, drop, create etc, only select insert)

    3) make mysql only accept connections from 127.0.0.1

    If someone has access to your box you have more problems than worrying about your applications db password.

提交回复
热议问题