已配置AllowNoPassword,为何phpMyAdmin仍拒绝root无密码登录?
解决phpMyAdmin无密码登录被禁止的问题
问题描述
我用以下Dockerfile搭建MySQL和phpMyAdmin环境(非生产环境,希望root无密码登录):
FROM ubuntu:latest # Install packages required for MySQL and phpMyAdmin RUN apt-get update && \ DEBIAN_FRONTEND=noninteractive apt-get install -y \ mysql-server \ phpmyadmin --no-install-recommends \ apache2 \ php \ php-mbstring \ php-zip \ php-gd \ php-json \ php-curl \ php-mysql \ curl # Disable password prompt for MySQL root user RUN echo "mysql-server mysql-server/root_password password ''" | debconf-set-selections && \ echo "mysql-server mysql-server/root_password_again password ''" | debconf-set-selections # Enable `AllowNoPassword` in phpMyAdmin RUN mv /usr/share/phpmyadmin/config.sample.inc.php /usr/share/phpmyadmin/config.inc.php && \ sed -i "/\$cfg\['Servers'\]\[\$i\]\['AllowNoPassword'\] = false;/d" /usr/share/phpmyadmin/config.inc.php && \ sed -i "/\$i++/i \$cfg['Servers'][$i]['AllowNoPassword'] = true;" /usr/share/phpmyadmin/config.inc.php # Enable some PHP mods RUN service apache2 start && \ phpenmod mbstring && \ service apache2 stop # Configure Apache to serve phpMyAdmin RUN echo "Include /etc/phpmyadmin/apache.conf" >> /etc/apache2/apache2.conf # Configure MySQL to be accessible from outside the container RUN sed -i 's/^.*bind-address.*$/bind-address = 0.0.0.0/' /etc/mysql/mysql.conf.d/mysqld.cnf && \ #If you dont want connections to linger, keep lines below uncommented echo "wait_timeout = 10" >> /etc/mysql/mysql.conf.d/mysqld.cnf && \ echo "interactive_timeout = 10" >> /etc/mysql/mysql.conf.d/mysqld.cnf && \ service mysql start && \ # Create a throwaway database mysql -u root -e "CREATE DATABASE mydatabase CHARACTER SET utf8mb3 COLLATE utf8mb3_general_ci" && \ # Creating a user with a blank password mysql -u root -e "CREATE USER 'root'@'%' IDENTIFIED WITH mysql_native_password BY ''" && \ mysql -u root -e "GRANT ALL PRIVILEGES ON *.* TO 'root'@'%' WITH GRANT OPTION" && \ mysql -u root -e "ALTER USER 'root'@'localhost' IDENTIFIED WITH mysql_native_password BY ''" && \ mysql -u root -e "GRANT ALL PRIVILEGES ON *.* TO 'root'@'localhost' WITH GRANT OPTION" && \ mysql -u root -e "FLUSH PRIVILEGES" && \ # Stop the MySQL service service mysql stop # Expose phpMyAdmin and MySQL port EXPOSE 80 3306 # Start services CMD service mysql start && \ service apache2 start && \ tail -f /var/log/apache2/access.log
运行容器后,MySQL客户端可以正常无密码连接,但访问localhost:80/phpmyadmin输入root且不填密码时,报错:Login without a password is forbidden by configuration (see AllowNoPassword)
当前生成的config.inc.php内容如下:
<?php /** * phpMyAdmin sample configuration, you can use it as base for * manual configuration. For easier setup you can use setup/ * * All directives are explained in documentation in the doc/ folder * or at <https://docs.phpmyadmin.net/>. */ declare(strict_types=1); /** * This is needed for cookie based authentication to encrypt password in * cookie. Needs to be 32 chars long. */ $cfg['blowfish_secret'] = ''; /* YOU MUST FILL IN THIS FOR COOKIE AUTH! */ /** * Servers configuration */ $i = 0; /** * First server */ $cfg['Servers'][$i]['AllowNoPassword'] = true; $i++; /* Authentication type */ $cfg['Servers'][$i]['auth_type'] = 'cookie'; /* Server parameters */ $cfg['Servers'][$i]['host'] = 'localhost'; $cfg['Servers'][$i]['compress'] = false; /** * phpMyAdmin configuration storage settings. */ /* User used to manipulate with storage */ // $cfg['Servers'][$i]['controlhost'] = ''; // $cfg['Servers'][$i]['controlport'] = ''; // $cfg['Servers'][$i]['controluser'] = 'pma'; // $cfg['Servers'][$i]['controlpass'] = 'pmapass'; /* Storage database and tables */ // $cfg['Servers'][$i]['pmadb'] = 'phpmyadmin'; // $cfg['Servers'][$i]['bookmarktable'] = 'pma__bookmark'; // $cfg['Servers'][$i]['relation'] = 'pma__relation'; // $cfg['Servers'][$i]['table_info'] = 'pma__table_info'; // $cfg['Servers'][$i]['table_coords'] = 'pma__table_coords'; // $cfg['Servers'][$i]['pdf_pages'] = 'pma__pdf_pages'; // $cfg['Servers'][$i]['column_info'] = 'pma__column_info'; // $cfg['Servers'][$i]['history'] = 'pma__history'; // $cfg['Servers'][$i]['table_uiprefs'] = 'pma__table_uiprefs'; // $cfg['Servers'][$i]['tracking'] = 'pma__tracking'; // $cfg['Servers'][$i]['userconfig'] = 'pma__userconfig'; // $cfg['Servers'][$i]['recent'] = 'pma__recent'; // $cfg['Servers'][$i]['favorite'] = 'pma__favorite'; // $cfg['Servers'][$i]['users'] = 'pma__users'; // $cfg['Servers'][$i]['usergroups'] = 'pma__usergroups'; // $cfg['Servers'][$i]['navigationhiding'] = 'pma__navigationhiding'; // $cfg['Servers'][$i]['savedsearches'] = 'pma__savedsearches'; // $cfg['Servers'][$i]['central_columns'] = 'pma__central_columns'; // $cfg['Servers'][$i]['designer_settings'] = 'pma__designer_settings'; // $cfg['Servers'][$i]['export_templates'] = 'pma__export_templates'; /** * End of servers configuration */ /** * Directories for saving/loading files from server */ $cfg['UploadDir'] = ''; $cfg['SaveDir'] = ''; /** * Whether to display icons or text or both icons and text in table row * action segment. Value can be either of 'icons', 'text' or 'both'. * default = 'both' */ //$cfg['RowActionType'] = 'icons'; /** * Defines whether a user should be displayed a "show all (records)" * button in browse mode or not. * default = false */ //$cfg['ShowAll'] = true; /** * Number of rows displayed when browsing a result set. If the result * set contains more rows, "Previous" and "Next". * Possible values: 25, 50, 100, 250, 500 * default = 25 */ //$cfg['MaxRows'] = 50; /** * Disallow editing of binary fields * valid values are: * false allow editing * 'blob' allow editing except for BLOB fields * 'noblob' disallow editing except for BLOB fields * 'all' disallow editing * default = 'blob' */ //$cfg['ProtectBinary'] = false; /** * Default language to use, if not browser-defined or user-defined * (you find all languages in the locale folder) * uncomment the desired line: * default = 'en' */ //$cfg['DefaultLang'] = 'en'; //$cfg['DefaultLang'] = 'de'; /** * How many columns should be used for table display of a database? * (a value larger than 1 results in some information being hidden) * default = 1 */ //$cfg['PropertiesNumColumns'] = 2; /** * Set to true if you want DB-based query history.If false, this utilizes * JS-routines to display query history (lost by window close) * * This requires configuration storage enabled, see above. * default = false */ //$cfg['QueryHistoryDB'] = true; /** * When using DB-based query history, how many entries should be kept? * default = 25 */ //$cfg['QueryHistoryMax'] = 100; /** * Whether or not to query the user before sending the error report to * the phpMyAdmin team when a JavaScript error occurs * * Available options * ('ask' | 'always' | 'never') * default = 'ask' */ //$cfg['SendErrorReports'] = 'always'; /** * You can find more configuration options in the documentation * in the doc/ folder or at <https://docs.phpmyadmin.net/>. */
尝试移动AllowNoPassword配置位置、使用--no-install-recommends安装均无效。
解决方案
问题根源
你的config.inc.php里犯了一个索引错误:
- 初始
$i = 0,你把AllowNoPassword = true赋值给了$cfg['Servers'][0] - 随后执行
$i++,$i变成1,后面的auth_type、host等配置都赋值给了$cfg['Servers'][1] - phpMyAdmin实际使用的是第1个服务器配置,而这个配置里没有开启
AllowNoPassword,所以报错。
修复步骤
方法1:修改Dockerfile中的sed命令
把原来修改phpMyAdmin配置的RUN指令替换成:
# Enable `AllowNoPassword` in phpMyAdmin RUN mv /usr/share/phpmyadmin/config.sample.inc.php /usr/share/phpmyadmin/config.inc.php && \ sed -i "/\$cfg\['Servers'\]\[\$i\]\['AllowNoPassword'\] = false;/d" /usr/share/phpmyadmin/config.inc.php && \ sed -i "/\$cfg\['Servers'\]\[\$i\]\['host'\] = 'localhost';/i \$cfg['Servers'][$i]['AllowNoPassword'] = true;" /usr/share/phpmyadmin/config.inc.php
这个修改会把AllowNoPassword = true插入到host配置的前面,此时$i的值还是0,和服务器的其他配置属于同一个索引。
方法2:直接修正config.inc.php
手动调整配置文件的顺序,确保AllowNoPassword和其他服务器配置在同一个$i索引下:
/** * Servers configuration */ $i = 0; /** * First server */ /* Authentication type */ $cfg['Servers'][$i]['auth_type'] = 'cookie'; /* Server parameters */ $cfg['Servers'][$i]['host'] = 'localhost'; $cfg['Servers'][$i]['compress'] = false; // 添加在同一个服务器配置块内 $cfg['Servers'][$i]['AllowNoPassword'] = true; $i++;
额外注意点
- 确保
$cfg['blowfish_secret']设置了32位字符串(虽然无密码登录可能暂时不影响,但cookie认证需要这个配置,避免其他潜在问题),比如:$cfg['blowfish_secret'] = 'abcdefghijklmnopqrstuvwxyz123456';
内容的提问来源于stack exchange,提问作者WeAreHawk09
相关产品推荐
相关产品推荐

