3 ms·
> I'd love to hear from the HN experts if that is a very bad idea Yes > and how to do it better. Put these users/passwords in the database like all the other
by rtlfe 6y ago
> I'd love to hear from the HN experts if that is a very bad idea
Yes
> and how to do it better.
Put these users/passwords in the database like all the other users so that you can shut them down when the passwords leak to the public.
- bzb3 6y agoYou can also shut the user down by removing the backdoor in the code.
- rtlfe 6y agoTo do it via code, you have to write the code change, run it to make sure you didn't break anything, get the code reviewed, wait for it to compile, and then deploy. In database, you run one simple query.
- mercer 6y agoThey are in the database and need to be added as users the regular way. It's just 'marking' them as superadmins that is done through a config file.
- boring_twenties 6y agoI don't understand, why not just add a column to the database with the permissions?