Quantcast

How to hide database user and password

classic Classic list List threaded Threaded
3 messages Options
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

How to hide database user and password

Hiller, Frank RD-PT31
I'm using PB version 1.0.3.
Database user and password are in repository_database.xml.
How can one hide usr + pwd? I'd prefer to have placeholders there and set both in source code.

Thanks...........Frank


Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: How to hide database user and password

John Eichelsdorfer
Maybe not an answer you are looking for, but I believe most applications rely on security of the operating system to provide the security of the database password.  What I mean is that if you have this under a Java application, the WEB-INF directory is secure or should be.  If not, your setup is likely not correct and your app should not be on the web.
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: How to hide database user and password

Armin Waibel
In reply to this post by Hiller, Frank RD-PT31
Hi Frank,

Hiller, Frank RD-PT31 wrote:
> I'm using PB version 1.0.3. Database user and password are in
> repository_database.xml. How can one hide usr + pwd? I'd prefer to
> have placeholders there and set both in source code.
>

http://db.apache.org/ojb/docu/faq.html#userPasswordNeeded

If you like to the convenience method to lookup a PB instance for one
PBKey (user, pwd combination) - PBF.defaultPersistenceBroker(), you can
set the PBKey in the PBF with PersistenceBrokerFactory#setDefaultKey at
start of our application.
Sorry but I don't remember if this works for version 1.0.3 ditto - give
it a try.

regards,
Armin

> Thanks...........Frank
>
>
>

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

Loading...