Every statement runs as an account and is checked against its privileges. This section builds that access control, then turns to SQL injection, the attack that rewrites your queries, and to the two defenses: server-side prepared statements and a least-privilege account (the PHP side is Databases with PDO). The listings change the whole server, so they run in order as root on a mysql:9.7 container of your own (Running MySQL in Docker) holding shop.
MENU
Users and Security
Users, Privileges, Roles, and SQL Injection