【问题标题】:Best Way to create configuration file(config.php) php [closed]创建配置文件(config.php)php的最佳方法[关闭]
【发布时间】:2015-04-21 05:05:38
【问题描述】:

我正在为我的项目创建一个数据库配置文件,但我不确定我的 config.php 是否安全。

如何修改此脚本以实现安全连接?

config.php

<?php
$username="root";
$password="";
$host="localhost";
$database="practise";
?>

Index.php

<?php
include 'config.php';
$con=mysql_connect("$host","$username","$password") or die("Server Error");
mysql_select_db("$database") or die("Database error");

if($con==true)
{
    echo "Success";
}
else
{
    mysql_close($con);
}
?>

【问题讨论】:

  • 这没有错。除了您使用mysql_*(已弃用)而不是mysqli 或pdo

标签: php mysql


【解决方案1】:

1) 创建一个config.php

define('DBUSER','username');
   define('DBPWD','password');
   define('DBHOST','localhost');
   define('DBNAME','database name');

2) db.php

 <?php
    include('config.php');
    class db extends mysqli {


        // single instance of self shared among all instances
        private static $instance = null;


        // db connection config vars
        private $user = DBUSER;
        private $pass = DBPWD;
        private $dbName = DBNAME;
        private $dbHost = DBHOST;

        //This method must be static, and must return an instance of the object if the object
        //does not already exist.
        public static function getInstance() {
        if (!self::$instance instanceof self) {
                self::$instance = new self;
        }
            return self::$instance;
        }

        // The clone and wakeup methods prevents external instantiation of copies of the Singleton class,
        // thus eliminating the possibility of duplicate objects.
        public function __clone() {
       trigger_error('Clone is not allowed.', E_USER_ERROR);
        }
        public function __wakeup() {
        trigger_error('Deserializing is not allowed.', E_USER_ERROR);
        }

        private function __construct() {
        parent::__construct($this->dbHost, $this->user, $this->pass, $this->dbName);
        if (mysqli_connect_error()) {
            exit('Connect Error (' . mysqli_connect_errno() . ') '
                    . mysqli_connect_error());
        }
        parent::set_charset('utf-8');

       }
       public function dbquery($query)
        {
            if($this->query($query))
            {
                return true;
            }

        }
        public function get_result($query) 
        {
            $result = $this->query($query);
            if ($result->num_rows > 0){
            $row = $result->fetch_assoc();
            return $row;
            } else
            return null;


        }
    }


    ?>

3) 用途

 require 'db.php';
    $query="select * from tbl_session";
    $sockets = db::getInstance()->get_result($query);

或任何其他查询

$query="insert into `tbl_chats` (coloum_name) values('".$val."')";
$wisherID = db::getInstance()->dbquery($query);

【讨论】:

    【解决方案2】:

    我找到了为我的项目创建 config.php 文件的最佳方法

    index.php

    <?php
    include 'config.php';
    try
    {
        $host=$config['DB_HOST'];
        $dbname=$config['DB_DATABASE'];
    $conn= new PDO("mysql:host=$host;dbname=$dbname",$config['DB_USERNAME'],$config['DB_PASSWORD']);
    //new PDO("mysql:host=$hostname;dbname=mysql", $username, $password);
    }
    catch(PDOException $e)
    {
        echo "Error:".$e->getMessage();
    }
    ?>
    

    config.php

    <?php
    $config=array(
    'DB_HOST'=>'localhost',
    'DB_USERNAME'=>'root',
    'DB_PASSWORD'=>'',
    'DB_DATABASE'=>'gobinath'
    );
    ?>
    

    【讨论】:

    • 这不是最好的方法。删除贬低的 mysql_* 函数。使用 mysqli_* 或 pdo 语句。
    • @ris 虽然正确,但与创建和使用配置文件无关
    • #pala_ 和 _@ris :更新我的 index.php 是最好的方法吗?
    【解决方案3】:

    我更喜欢在配置选项中使用常量而不是变量,原因有以下三个:

    1. 它们是全局的,因此无需将它们作为参数注入函数或使用global 关键字,
    2. 应用程序本身无法更改它们(如果您不小心,可能会发生意外并导致一些尴尬的错误),
    3. 优秀的编辑器提供代码完成功能,可以导航到声明常量的行。这使得处理具有很多选项的大型项目变得更加容易。这也适用于全局变量,但常量有点“干净”(经验法则是保持全局范围尽可能干净)。

    例子:

    <?php
    
    const DB_HOST = 'localhost';
    const DB_USER = 'user123';
    const DB_PASS = '';
    const DB_NAME = 'test';
    

    索引:

    <?php
    
    require_once 'config.php';
    
    $link = new MySQLi(DB_HOST, DB_USER, DB_PASS, DB_NAME);
    

    【讨论】:

      【解决方案4】:

      这是我的 config.php 的正确方法

      <?php
      include 'config.php';
      try
      {
          $host=$config['DB_HOST'];
          $dbname=$config['DB_DATABASE'];
      $conn= new PDO("mysql:host=$host;dbname=$dbname",$config['DB_USERNAME'],$config['DB_PASSWORD']);
      //new PDO("mysql:host=$hostname;dbname=mysql", $username, $password);
      }
      catch(PDOException $e)
      {
          echo "Error:".$e->getMessage();
      }
      ?>
      

      config.php

      <?php
      $config=array(
      'DB_HOST'=>'localhost',
      'DB_USERNAME'=>'root',
      'DB_PASSWORD'=>'',
      'DB_DATABASE'=>'gobinath'
      );
      ?>
      

      【讨论】:

      • 配置文件在哪里?这就是他问的问题
      • @cwyatt1:添加了 config.php 以供参考
      猜你喜欢
      • 1970-01-01
      • 2012-01-15
      • 1970-01-01
      • 2012-12-17
      • 2021-01-21
      • 1970-01-01
      • 2023-03-06
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多