I find out this.
On default/settings.php is it okay to have clear text user and pass for the DB here?

What if the site go production? Is it safe?

Regards

Comments

pramudya81’s picture

Anyone faced the same issue here?

bonaparte’s picture

As long as you can restrict access to the settings.php file, you are safe. This is how database passwords are generally stored in web applications.
--------------------
Sudheer. S
Binary Vibes Information Technologies Pvt. Ltd.
LAMP
Binary Vibes

pramudya81’s picture

bonaparte,

hmm how we then restrict access to this file?
Sorry I'm very new to this drupal and web world.

Could you share some knowledge?

Regards

bonaparte’s picture

It depends on your server set up. If you are hosting your site on a shared server, typical for small websites, the hosting company would have provided you an account. Only the server administrator and the account owner has access to your files including settings.php.

Visitors cannot download files with .php extension unlike text, images and archive files.

--------------------
Sudheer. S
Binary Vibes Information Technologies Pvt. Ltd.
LAMP
Binary Vibes

pramudya81’s picture

Hmm ok thanks for your info.

pramudya81’s picture

What about creating a kind of connection pooling - Data Source on My Sql Database?

Is it possible? Then we call this conn pool / Data Source name from settings.php?

Really needs guide on this.

Regards

bonaparte’s picture

I think you are complicating things for yourself.
--------------------
Sudheer. S
Binary Vibes Information Technologies Pvt. Ltd.
LAMP
Binary Vibes

pramudya81’s picture

Yup, complex is a fine price for best performance and security right?

But in a mean time looking for this information. I'll just do what you suggested

Regards