Static Authentication

  • trochford
  • Auteur du sujet
  • Hors Ligne
  • Nouveau membre
  • Nouveau membre
  • MAXOS Developer
Plus d'informations
il y a 13 ans 3 mois #26 par trochford
Static Authentication a été créé par trochford
Could the static credentials be hived off into a separate text file so they can be maintained without the potential of breaking the php. There are many situations where this will be the best solution, e.g. in Adult & Community Learning, where a central directory of users is not maintained. The text file would then be 'included' in static.php.

Connexion ou Créer un compte pour participer à la conversation.

Plus d'informations
il y a 13 ans 2 semaines #408 par JohnSmith
Réponse de JohnSmith sur le sujet Static Authentication
Hi Thomas,

Sorry, just looking through some questions that have been sitting unanswered for a while and came across this...

The problem I see would be that a plain text file could be reached and would be displayed by a browser. Whilst an incorrectly formatted PHP file usually breaks the page, it does give immediate indication that something isn't right and therefore login details 'probably' wouldn't show...

I wouldn't generally recommend storing plain passwords in a text file like this and would never use it on a production server. I think the best option would be to use the Db authentication in most instances where at least the passwords are hashed and provide some security...

John

Connexion ou Créer un compte pour participer à la conversation.

Modérateurs: JohnSmith
Temps de génération de la page : 0.122 secondes
Copyright © 2026 The Xerte Project.
Xerte logo Apereo logo OSI Logo