[Phpmyadmin-devel] Re: always include db and table names in generated querys

Michal Čihař michal at cihar.com
Mon Feb 20 03:17:01 CET 2006


Hi

On Sun, 19 Feb 2006 09:50:26 +0100
Sebastian Mendel <lists at sebastianmendel.de> wrote:

> while working on bug #1431615 'Exporting specific rows from query with join'
> 
> i wonder if it would be wise to always include db and table names in 
> references used in queries generated by phpMyAdmin?
> 
> i think it does no harm to add this, and it is more secure as it is 
> absolutely sure what column is meant by this query, especially with 
> delete queries - if ever in error a wrong database is selected before 
> delete query is executed.

You're right for internal queries. This can not be applied to export.

-- 
	Michal Čihař | http://cihar.com
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: <http://lists.phpmyadmin.net/pipermail/developers/attachments/20060220/b8a2097c/attachment.sig>


More information about the Developers mailing list