FiveM MySQL Access Denied for User Error 1045 แก้อย่างไร? ตรวจ Username, Password, User@Host และ Authentication Plugin ให้ถูกจุด
ปัญหา FiveM MySQL/MariaDB ขึ้น Access denied for user หรือ Error 1045 หมายความว่า FiveM สามารถติดต่อ MariaDB ได้ถึงขั้น Authentication แล้ว แต่ Database ไม่ยอมให้ Account นั้นเข้าสู่ระบบตามข้อมูลหรือสิทธิ์ที่กำหนดไว้
MariaDB กำหนด Error 1045, SQLSTATE 28000 เป็น:
ER_ACCESS_DENIED_ERRORAccess denied for user '%s'@'%s' (using password: %s)
และเอกสาร MariaDB ระบุสาเหตุสำคัญ เช่น Username/Password Combination ไม่มีอยู่ หรือ User ไม่มีสิทธิ์สำหรับ Database ที่กำลังพยายามเข้าถึง.
ตัวอย่าง:
ERROR 1045 (28000):Access denied for user 'fivem'@'10.0.0.20'(using password: YES)
สำหรับ FiveM ปัญหานี้มักเกิดหลัง:
- เปลี่ยนรหัส Database
- ย้าย VPS
- ย้าย MariaDB
- Clone Server
-
แก้
server.cfg - เปลี่ยน Connection String
- เปลี่ยน Database User
- Restore Database แต่ไม่ได้ Restore Account/Privileges
- เปลี่ยน Authentication Plugin
- ใช้ User ถูกชื่อแต่ Host ไม่ตรง
- Production/Test Config สลับกัน
- Password มีอักขระพิเศษแล้ว Connection String Parse ผิด
- Resource ใช้ Database Credential คนละชุดกับ Core Server
หลักการแก้ที่ถูกต้องคือ:
อ่าน Error 1045 ให้ครบ↓ดู username@host↓ดู using password YES/NO↓ตรวจ Connection String↓ตรวจ Account ที่ MariaDB มีจริง↓ตรวจ Authentication Plugin↓ตรวจ SHOW GRANTS↓ทดสอบจาก FiveM Host จริง↓แก้เฉพาะ Root Cause
① FiveM MySQL Error 1045 คืออะไร
MariaDB Error 1045 คือ:
104528000ER_ACCESS_DENIED_ERROR
พร้อมข้อความ:
Access denied for user 'user'@'host'(using password: YES/NO)
MariaDB Documentation จัด Error นี้เป็น Authentication/Access Error โดยตรง.
② Error นี้ต่างจาก Error 1130 อย่างไร
หัวข้อก่อนหน้า Error 1130 คือ:
Host is not allowed to connect
เน้นว่า Host ไม่มี Account ที่ได้รับอนุญาตให้เชื่อมเข้ามา
ส่วน 1045 คือ:
Access denied for user
แปลว่าการเชื่อมต่อมาถึงขั้นที่ MariaDB พยายาม Authenticate Account แล้วแต่ไม่ผ่าน.
③ จำง่าย ๆ
1130 = Host ไม่ผ่าน1045 = User/Authentication ไม่ผ่าน
④ ต่างจาก Error 1044 อย่างไร
MariaDB Error Code Reference แยก:
1044 = Access denied for user ... to database ...1045 = Access denied for user ... (using password ...)
ดังนั้น 1044 จะเน้นการเข้าถึง Database ที่ระบุ ส่วน 1045 เน้น Authentication/Account Access มากกว่า.
⑤ Error 1045 เป็น SQL Syntax Error หรือไม่
ไม่
SQL Syntax Error ทั่วไปคือ 1064
1045 เกิดก่อน Gameplay Query จะทำงานตามปกติ เพราะ Connection Authentication ไม่ผ่าน
⑥ using password: YES หมายความว่าอะไร
หมายความว่า Client Attempt นั้นส่งข้อมูล Password มาในการ Authentication
ไม่ได้แปลว่า Password ที่ส่งมานั้นถูก
⑦ using password: NO หมายความว่าอะไร
หมายความว่า Connection Attempt นั้นไม่ได้ส่ง Password ในรูปแบบที่ Error Report รับรู้
ถ้า Account ต้องใช้ Password:
นี่เป็นเบาะแสสำคัญ
⑧ อย่าสับสน YES กับ “Password ถูก”
ตัวอย่าง:
Access denied ...(using password: YES)
แปลเพียง:
มี password ถูกส่งมา
ไม่ใช่:
password ถูกต้อง
⑨ สาเหตุที่พบบ่อยที่สุด — Password ผิด
เช่น Database Password จริงคือ:
NewPassword
แต่ FiveM ยังใช้:
OldPassword
Connection จะถูกปฏิเสธ
⑩ Error หลังเปลี่ยน Database Password
นี่เป็น Pattern ที่ตรงมาก
Flow:
MariaDB password changed↓FiveM config ยังเป็น password เก่า↓resource reconnect↓1045 Access denied
⑪ ต้องตรวจ Connection String
ดูค่าที่ FiveM ใช้จริง เช่น:
hostportdatabaseusernamepassword
⑫ อย่าโพสต์ Connection String เต็มต่อสาธารณะ
โดยเฉพาะ:
password
ต้อง Mask ก่อนแชร์ Logs
⑬ Password Copy/Paste ผิดได้
เช่นมี:
- Space นำหน้า
- Space ท้าย
- Newline
- Character หาย
จึงควรตรวจค่าอย่างระมัดระวัง
⑭ Password มีอักขระพิเศษ
ถ้า Connection String ใช้ URI-style Syntax:
อักขระบางตัวอาจมีความหมายพิเศษใน URI/Connector
จึงควรใช้ Encoding หรือ Connection Format ตาม Database Wrapper ที่ FiveM ใช้อยู่จริง
⑮ อย่าเปลี่ยน Password ให้เป็น 1234 เพื่อทดลอง Production
ลด Security โดยไม่จำเป็น
หากสงสัย Parsing:
ใช้วิธี Config/Encoding ที่ Wrapper รองรับ
⑯ Username ผิดก็ทำ 1045 ได้
ตัวอย่าง:
Database Account จริง:
fivem_prod
แต่ Config:
fivem
MariaDB สามารถ Reject ได้
⑰ Error Message บอก Username ที่ถูกใช้จริง
เช่น:
Access denied for user 'fivem_test'@'10.0.0.20'
นี่เป็นข้อมูลสำคัญมาก
เพราะแสดงว่า FiveM กำลังใช้:
fivem_test
ไม่ใช่ Account ที่คุณคิด
⑱ ตรวจ Config หลายจุด
FiveM Server บางตัวอาจมี Connection Settings มากกว่า 1 แห่ง เช่น:
- Core DB
- Phone DB
- Logs DB
- External API
⑲ Resource เดียว Error 1045
ถ้า:
inventory ปกติgarage ปกติbank ปกติphone error 1045
Phone Resource อาจใช้ Database Credential แยก
⑳ ทุก Resource Error 1045
มีโอกาสสูงว่า Core Database Connection/Wrapper ใช้ Account ผิด
㉑ MariaDB Account ไม่ได้มีแค่ Username
MariaDB Account ใช้รูปแบบ:
'user'@'host'
และ Authentication Configuration ผูกกับ Account นั้น.
㉒ ตัวอย่าง
'fivem'@'localhost'
กับ:
'fivem'@'10.0.0.20'
เป็นคนละ Account Context
㉓ Password เดียวกันก็ไม่ได้แปลว่าใช้แทนกันได้
ถ้า Host Matching เลือก Account คนละตัว:
Authentication Configuration และ Privileges อาจต่างกัน
㉔ Error หลังย้าย FiveM VPS
เดิม FiveM มาจาก:
10.0.0.10
ใหม่มาจาก:
10.0.0.20
Account ที่ MariaDB Match อาจเปลี่ยน
㉕ หาก Host ไม่ได้รับอนุญาตเลย
อาจเจอ 1130 มากกว่า
แต่ถ้า Account Matching มาถึง Authentication แล้วข้อมูลไม่ถูกต้อง:
อาจเจอ 1045
㉖ อย่าดู Username อย่างเดียว
อ่านข้อความเต็ม:
'user'@'host'
เสมอ
㉗ SHOW CREATE USER มีประโยชน์มาก
MariaDB มี:
SHOW CREATE USER 'user'@'host';
เพื่อแสดง SQL ที่สามารถสร้าง Account เดิมกลับมา รวมถึง Authentication Details.
㉘ ตัวอย่าง
SHOW CREATE USER 'fivem'@'10.0.0.20';
ใช้ Account จริงของ Server
㉙ ทำไมต้องดู SHOW CREATE USER
เพราะช่วยตรวจ:
- Authentication Plugin
- Account Definition
- Authentication Configuration
โดยไม่ต้องเดา
㉚ Authentication Plugin คืออะไร
MariaDB รองรับระบบ Authentication แบบ Plugin และ Account สามารถกำหนด Plugin ที่ใช้ Authenticate ได้ผ่าน CREATE USER ... IDENTIFIED VIA/WITH ....
㉛ FiveM ต้องสนใจ Plugin ไหม
ถ้า Account ใช้ Authentication Plugin ที่ Database Connector ของ FiveM ไม่รองรับหรือ Config ไม่ตรง:
Authentication อาจล้มเหลว
㉜ MariaDB รองรับหลาย Authentication Plugins
เอกสาร MariaDB ระบุว่า Account สามารถผูกกับ Authentication Plugins และในรุ่นใหม่สามารถกำหนดหลาย Plugin ให้ Account ได้ด้วย.
㉝ อย่าเปลี่ยน Authentication Plugin แบบสุ่ม
เช่นเห็น 1045แล้วเปลี่ยนทุก Userเป็น:
mysql_native_password
ทันที
ต้องตรวจ:
- MariaDB version
- Wrapper support
- Account ที่กำลังใช้
ก่อน
㉞ mysql_native_password
MariaDB มี Authentication Plugin นี้และเอกสารอธิบายการสร้าง Account/Password สำหรับ Plugin โดยตรง.
㉟ แต่ไม่ใช่ Plugin เดียว
MariaDB มี Plugin อื่น เช่น:
- unix_socket
- PAM
- ed25519
- GSSAPI
ตาม Environment.
㊱ FiveM Application Account ควรใช้ Plugin ไหน
ไม่มีคำตอบสากลโดยไม่รู้ Database Connector ที่ FiveM ใช้
ควรใช้ Authentication Method ที่:
- MariaDB รองรับ
- Database Wrapper รองรับ
- Security Policy อนุญาต
㊲ Root Account อาจใช้ unix_socket
MariaDB Documentation ปัจจุบันระบุว่า root@localhost ที่สร้างโดย mariadb-install-db สามารถถูกตั้งให้ใช้ unix_socket Authentication ได้ในหลาย Installation.
㊳ ทำไม sudo mariadb เข้าได้แต่ใช้ Password ไม่ได้
อาจเป็นเพราะ Root Account ใช้ unix_socket
ไม่ได้หมายความว่า Password ของ Application ใช้งานได้
㊴ FiveM ไม่ควรใช้ root เพราะเหตุนี้
FiveM Application ควรมี Dedicated MariaDB Account
ไม่ควรใช้ root เพื่อหลีกเลี่ยง Authentication Problem
㊵ unix_socket เหมาะกับ Remote FiveM ไหม
โดยธรรมชาติ Plugin นี้อาศัย Unix Socket/OS User Context บน Host เดียวกัน จึงไม่ได้ออกแบบเป็น Remote Password Authentication ทั่วไป.
㊶ ดังนั้น Dedicated Application Account สำคัญ
เช่น:
fivem application↓dedicated DB user↓supported auth plugin↓required privileges only
㊷ ตรวจ Account ด้วย SHOW CREATE USER
ตัวอย่าง:
SHOW CREATE USER 'fivem'@'10.0.0.20';
ถ้า Plugin ไม่ตรงกับ Connector Requirement:
แก้ Account ตาม Documentation ของ MariaDB/Wrapper
㊸ อย่า UPDATE ตาราง mysql.user ตรง ๆ
ใช้ Account Management Statements เช่น:
- CREATE USER
- ALTER USER
- SET PASSWORD
- GRANT
ตาม Version ที่รองรับ
㊹ ALTER USER
MariaDB มี ALTER USER สำหรับเปลี่ยน Authentication Properties ของ Account.
㊺ แต่ก่อน ALTER
ต้อง Backup/จด Account Definition ไว้
เช่นใช้:
SHOW CREATE USER ...
เพื่อมี Reference
㊻ Error หลัง MariaDB Upgrade
Authentication Behavior/Plugins อาจต่างจาก Environment เดิม
จึงควรตรวจ:
SHOW CREATE USER ...
หลัง Upgrade
㊼ Error หลัง Restore Database
สิ่งสำคัญคือ Application Tables กับ MariaDB Accounts เป็นคนละส่วนของระบบ
การ Restore Gameplay Database ไม่ได้หมายความว่า Application Account/Authentication จะถูก Restore ตามแบบที่ต้องการเสมอไป
㊽ Server Migration Checklist
ควรตรวจ:
Database dataDatabase userUser@HostPasswordAuthentication pluginGrantsFirewallConnection string
㊾ Error หลัง Clone Production
Clone Config อาจยังใช้:
production user
กับ Test Server
㊿ Production MariaDB อาจ Reject Host ใหม่
หรือ Test Server อาจเข้าถึง Production โดยไม่ตั้งใจ
ดังนั้นอย่าแก้ด้วยการเปิดกว้างทันที
51. Test Database ควรแยก
ถ้าเป็นไปได้
ลดความเสี่ยงจาก:
- Resource Migration
- DELETE
- Schema Changes
- Test Transactions
52. Error 1045 อาจช่วยป้องกัน Production
ถ้า Test Host ไม่ควรเข้า Production DB แล้วถูก Reject:
อย่ารีบ Grant Access ก่อนตรวจ Architecture
53. Error หลังแก้ Password แล้วไม่หาย
ตรวจ User@Host
เพราะอาจแก้ Password ให้ Account:
'fivem'@'localhost'
แต่ FiveM กำลัง Match:
'fivem'@'10.0.0.20'
54. Account คนละตัว
การเปลี่ยน Password ตัวหนึ่งไม่ได้เปลี่ยนอีกตัว
55. SHOW CREATE USER ทั้งสอง Account
ช่วยให้เห็นความแตกต่าง
56. SHOW GRANTS ใช้ทำอะไร
MariaDB SHOW GRANTS แสดง Privileges ที่กำหนดให้ Account นั้น.
ตัวอย่าง:
SHOW GRANTS FOR 'fivem'@'10.0.0.20';
57. Error1045กับ Privilegesเกี่ยวไหม
MariaDB Error 1045 Documentation ระบุ Possible Cause รวมถึง User ไม่มี Privilege บน Database ที่พยายามเข้าถึง.
ดังนั้นหาก Credentials ถูก:
ต้องตรวจ Grants ด้วย
58. แต่ Login ไม่ผ่านตั้งแต่แรก
ให้เริ่มจาก:
- Account
- Host
- Password
- Plugin
ก่อน
59. ถ้า Login ผ่านแต่ USE database ไม่ได้
MariaDB Connection Troubleshooting Guide ระบุว่าหาก User เชื่อมได้แต่ไม่มีสิทธิ์ Database นั้น ให้ Grant Privileges ที่จำเป็นบน Database ให้ Account.
60. Error อาจเปลี่ยนหลังแก้ Authentication
เช่น:
1045
หายแล้วกลายเป็น:
command denied
นี่อาจหมายถึง Connectionผ่านแล้วแต่ Privilegesยังไม่พอ
61. ไม่ควร Grant ALL ON *.*
เพียงเพราะต้องการให้ Error หาย
62. Principle ที่ดีกว่า
ให้ Application Account เข้าถึงเฉพาะ:
Database ที่ FiveM ใช้
และ Privileges เท่าที่ Resource ต้องใช้
63. FiveM Runtime มักต้องทำอะไร
ขึ้นกับ Framework/Resources แต่โดยทั่วไปอาจมี:
- SELECT
- INSERT
- UPDATE
- DELETE
ส่วน Schema Migrations บาง Resource อาจต้อง Permissions เพิ่ม
64. อย่าเดา Permission Set
อ่าน Resource Documentation
65. Runtime Account กับ Migration Account
ระบบที่เข้มขึ้นสามารถแยกสองบทบาทได้
แต่ไม่จำเป็นต้องทำทันทีในทุก FiveM Server
66. Error หลัง Resource Auto Migration
ถ้า Authentication ผ่านแต่ Migrationไม่มี Privilege:
Error จะเป็น Permission/DDL Error มากกว่า 1045
อ่าน Consoleต่อไป
67. CURRENT_USER() มีประโยชน์หลัง Connect ได้
MariaDB CURRENT_USER() แสดง Account User/Host ที่ Server ใช้ Authenticate Session จริง.
ใช้:
SELECT CURRENT_USER();
68. ทำไมมีประโยชน์
คุณอาจคิดว่า MariaDBใช้:
'fivem'@'%'
แต่จริง ๆ Match Accountเฉพาะกว่าอีกตัว
69. USER() กับ CURRENT_USER() อาจต่างกัน
ในการวิเคราะห์ Account Matching สิ่งสำคัญคือ Account ที่ MariaDB ใช้ Authenticate จริง
70. แต่ถ้า Error1045ยังอยู่
ยัง Query CURRENT_USER() จาก Connection นั้นไม่ได้
ต้องใช้ Admin Session ตรวจ Accountก่อน
71. SHOW CREATE USER มีความแม่นกว่าเดา Config
เพราะแสดง Account Definitionจาก MariaDBจริง.
72. Errorหลัง Server Restart
ถ้า Database Passwordถูกเปลี่ยนแบบ Runtime/Configไม่สอดคล้อง:
อาจเพิ่งแสดงผลหลัง Restart
73. Errorก่อน Restartไม่เกิด
แต่หลัง Restartเกิด:
ตรวจว่า MariaDB โหลด Account/Plugin/Config ตามที่คาดหรือไม่
74. FiveM Connection Stringก็อาจ Loadใหม่หลัง Restart
ถ้าเดิม Processยังใช้ค่าเก่าใน Memory
Restart Resourceแล้วอาจใช้ค่า Configใหม่ที่ผิด
75. Errorหลังแก้ server.cfg
ย้อนดู Diff
โดยเฉพาะ Connection String
76. Quotes ใน Config
ตรวจ:
- quote เปิด/ปิด
- whitespace
- special characters
ตาม Syntaxของ Wrapper
77. อย่าใช้ Syntax จาก Wrapper คนละตัว
ตัวอย่าง Optionsของ Database Clientหนึ่ง:
อาจไม่รองรับในอีกตัว
78. FiveM Database Wrapper Version สำคัญ
Connection String Format หรือ Connector Support อาจเปลี่ยนตาม Version
ใช้ Official Docsของ Wrapperนั้น
79. Errorหลังย้ายจาก mysql-async ไป oxmysql หรือ Database Wrapper ใหม่
ตรวจ:
- connection string format
- supported authentication
- resource compatibility
80. อย่ารัน Wrappersหลายตัวเพียงเพื่อแก้1045
1045เป็น Authentication Issue
เพิ่ม Wrapperอีกตัวไม่ได้ทำ Password/Userถูกขึ้นมา
81. Error using password: NO
ตรวจว่า Connection String มี Password field จริงหรือไม่
82. Environment Variable ว่าง
ตัวอย่าง:
DB_PASSWORD=
อาจทำให้ Clientส่งไม่มี Password
83. Secret Manager/Panel
หาก Passwordถูกเก็บผ่าน Hosting Panel:
ตรวจว่าค่า Environmentถูกส่งเข้า FiveM Processจริง
84. Docker Compose
Environment Variable Nameผิดหนึ่งตัว:
Applicationอาจใช้ค่า Empty
85. แต่ไม่ควร Print Secretทั้งหมดเพื่อ Debug
แสดงเพียง:
password loaded = yes/no
ใน Developmentอย่างปลอดภัยก็เพียงพอ
86. Error using password: YES
ตรวจว่า Passwordตรง Accountที่ Matchหรือไม่
87. Password ของ Account Host-specific
Account:
'fivem'@'localhost'
กับ:
'fivem'@'%'
อาจตั้ง Passwordไม่เหมือนกัน
88. จึงต้องรู้ Accountที่ Matchจริง
ไม่ใช่ Resetทุก Accountชื่อ fivem
89. อย่า Reset Passwordหลาย Accountsพร้อมกัน
อาจทำ Applicationsอื่นใช้งานไม่ได้
90. แยก User ต่อ Application
ช่วยลดความสับสน เช่น:
fivem_appwebsite_appbackup_app
91. ช่วย Securityด้วย
เพราะแต่ละ Applicationสามารถมี Privilegesต่างกัน
92. Errorหลัง Website Password Change
ถ้า FiveMใช้ Userเดียวกับ Website:
การเปลี่ยน Password Websiteอาจทำ FiveMเสียด้วย
นี่เป็นอีกเหตุผลให้แยก Application Accounts
93. Shared Database User ไม่ผิดเสมอไป
แต่เพิ่ม Coupling และทำ Troubleshootingยากขึ้น
94. Errorหลัง Hosting Provider Reset DB Password
FiveM Connection String ต้อง Updateให้ตรง
95. Errorหลัง Import User Tableจาก Serverเก่า
ไม่ควร Copy System Account Tablesข้าม Versionแบบสุ่ม
ใช้ MariaDB Migration/Account-management วิธีที่เหมาะสมกว่า
96. Authentication Plugin Compatibility
MariaDB Pluggable Authentication Documentation ระบุว่า Accountสามารถกำหนด Authentication Pluginผ่าน IDENTIFIED VIA/WITH และ Pluginต้องติดตั้ง/Activeบน Server.
97. Pluginไม่มี
Authenticationอาจไม่ทำงานตามที่ Accountถูกกำหนด
98. ตรวจ Plugin
Adminสามารถตรวจ Active Pluginsตาม MariaDB Documentation
แต่ไม่ควร INSTALL Pluginเพียงเพราะ1045โดยไม่มีหลักฐาน
99. Errorหลังเปลี่ยน Plugin
ถ้า:
ก่อน = ทำงานหลัง ALTER USER plugin = 1045
Rollback/แก้ตาม MariaDB Documentationและ Connector Support
100. MariaDB 10.4+ Authentication
MariaDB Documentation อธิบายว่า Account Authentication Model สามารถใช้หลาย Authentication Methods ใน Accountเดียวได้ใน Versionsใหม่.
101. นี่ทำให้ Account Diagnosisซับซ้อนขึ้น
จึงควรดู:
SHOW CREATE USER ...
แทน Guess
102. Errorหลังเปลี่ยน root Password
FiveMไม่ควรใช้ rootตั้งแต่แรก
ถ้าใช้:
ควรย้ายไป Dedicated Application Accountอย่างเหมาะสม
103. ห้ามใช้ skip-grant-tables เพื่อแก้ 1045 ปกติ
มัน Bypass Authentication/Privilege Checks และเหมาะกับ Recovery Scenariosเฉพาะ ไม่ใช่ Application Fix
104. อย่าปิด Authenticationทั้งระบบ
เพียงเพื่อให้ FiveMเชื่อมได้
105. Error1045ไม่ใช่เหตุผลเปิด Database Public
FirewallและAuthenticationเป็น Security Layersคนละส่วน
106. Remote Database
ถ้า FiveMกับMariaDBคนละเครื่อง:
ต้องตรวจ:
FiveM source hostMariaDB account hostcredentials
ร่วมกัน
107. ถ้า Firewall Block
มักจะได้ Connection Timeout/Refused มากกว่า 1045
เพราะ Connectionยังไปไม่ถึง Authentication
108. ดังนั้น 1045เป็นสัญญาณว่าการเชื่อมไปถึง MariaDBในระดับ Authenticationแล้ว
จึงไม่ควรเริ่มด้วยการเปิด Firewallกว้างขึ้น
109. Errorหลังเปลี่ยน IP FiveM
Account Matchingอาจเปลี่ยน
ตรวจ User@Hostก่อน Reset Password
110. NAT
MariaDBอาจเห็น Source Hostที่ต่างจาก IPใน FiveM Machine
111. VPN
เช่นเดียวกัน
การเปิด/ปิด VPNอาจเปลี่ยน Hostที่ MariaDBเห็น
112. Docker
Container Networkอาจทำให้ Host Matchingต่างจาก Public IP
113. Cloud Private Network
อาจเห็น Private IPเป็น Source
นี่เป็นสาเหตุที่ควรอ่านข้อความ:
'user'@'host'
จาก Errorจริง
114. อย่า Mask Hostจนตัวเอง Debugไม่ได้
แชร์ Publicค่อย Maskบางส่วน
แต่ในการตรวจภายในต้องรู้ Sourceจริง
115. Password ถูกแต่ยัง 1045
Checklist:
Account ชื่อถูก?Host ถูก?Authentication plugin ถูก?Database privilege ถูก?Connection String ชี้ server ถูก?
116. Connection String ชี้ DB คนละ Server
เกิดได้หลัง Migration
คุณอาจ Reset Passwordบน:
db-new
แต่ FiveMยังเชื่อม:
db-old
จึงยัง1045
117. ทดสอบด้วย MariaDB Client จาก FiveM Host
นี่เป็นวิธีแยก:
Database account problem
ออกจาก:
FiveM wrapper config problem
118. ถ้า CLIจาก FiveM Hostก็1045
ปัญหาอยู่ที่ Account/Credentials/Authenticationเป็นหลัก
119. ถ้า CLIผ่านแต่ FiveM1045
ตรวจ FiveM Connection String/Wrapper
120. ใช้ Credentialเดียวกันในการ Test
แต่ทำอย่างปลอดภัย
อย่าใส่ Passwordใน Shell Historyถ้า Toolมีวิธี Prompt Password
121. Test จาก Laptopไม่พอ
เพราะ:
'user'@'laptop-host'
อาจ Match Accountคนละตัวกับ:
'user'@'fivem-host'
122. ต้อง Test จาก Hostเดียวกับ FiveM
เพื่อให้ Account Matchingใกล้เคียง Productionจริง
123. SHOW GRANTS
หลังรู้ Accountที่ Matchแล้ว:
ตรวจ:
SHOW GRANTS FOR 'fivem'@'host';
MariaDB Connection Troubleshooting Guide ระบุว่าหาก Userไม่มีสิทธิ์ Databaseให้ Grant Privilegesที่จำเป็น.
124. อย่าดู Grantsของ Accountผิด Host
เช่นดู:
'fivem'@'localhost'
แต่ FiveMใช้:
'fivem'@'10.0.0.20'
จะทำให้วิเคราะห์ผิด
125. Errorหลังสร้าง Userแต่ลืม Grant
Connectionอาจ Authenticationผ่านบางขั้นแต่เข้า Databaseที่ระบุไม่ได้
126. Database ใน Connection String
ถ้า Connection Stringระบุ Databaseที่ Accountไม่มีสิทธิ์:
MariaDB Error1045 Documentationระบุ Privilegeบน Databaseเป็น Possible Cause.
127. ทดลองเชื่อมโดยไม่ระบุ Database
ใน Troubleshooting Environmentที่ปลอดภัยอาจช่วยแยกว่า:
- Authenticationผ่านหรือไม่
- Database-specific privilegeเป็นปัญหาหรือไม่
ใช้ตาม MariaDB Client/Environment
128. แต่ FiveM Productionต้องใช้ Databaseจริง
สุดท้าย Privilegesต้องถูกต้อง
129. Errorหลังเปลี่ยน Database Name
เช่น:
fivem_old
→
fivem_prod
Userเดิมอาจไม่มี Grantsบน Databaseใหม่
130. GRANTใหม่ต้องระบุ Databaseถูก
อย่าพิมพ์ชื่อผิด
131. Underscore/Wildcard ใน GRANT
การอ้าง Database Namesใน Privilege Statementsต้องใช้ Syntaxให้ถูกต้อง
โดยเฉพาะชื่อที่มี Characterพิเศษ
132. SHOW GRANTSช่วยตรวจสิ่งที่ Serverใช้จริง
ดีกว่าดู Script Migrationอย่างเดียว
133. access_denied_errors
MariaDB มี Status/Monitoringเกี่ยวกับ Access Denied Events และเอกสารระบุว่า Failed Logins, Invalid Privileges หรือ SSL Requirementที่ไม่ผ่านสามารถทำ Access Denied Countersเพิ่มได้.
134. นี่มีประโยชน์ด้าน Security Monitoring
ถ้า1045เกิดจำนวนมาก:
ต้องแยกว่าเป็น:
- Configผิด
- Resource Retry
- Unknown Login Attempts
135. 1045 จำนวนมากไม่ได้แปลว่าโดน Hackทันที
Applicationที่ใช้ Passwordเก่าก็สร้าง1045เป็นพันครั้งได้
136. ดู Source Host
ถ้ามาจาก FiveM VPSหลังเปลี่ยน Password:
Root Causeมีเหตุผลชัด
137. ถ้ามาจาก Unknown Internet Hosts
และ Databaseเปิด Public:
ควรตรวจ Network Exposure/Security
138. แต่ไม่ควรตอบด้วยเปลี่ยน Portอย่างเดียว
Securityต้องดู:
- Firewall
- Host ACL
- Accounts
- Password
- TLS
ตาม Architecture
139. Retry Storm
ถ้า FiveM Wrapper Authentication Failแล้ว Retryรัว:
Error Logอาจเต็มด้วย1045
140. อย่าแก้ด้วยเพิ่ม max_connect_errors
1045เป็น Authentication Failure
และการเพิ่ม Connection Error Thresholdไม่ได้ทำ Credentialsถูก
141. อย่าเพิ่ม max_connections
เช่นเดียวกัน
1045ไม่ได้เกิดจาก Connection Slotsเต็ม
142. อย่าเพิ่ม wait_timeout
ไม่เกี่ยว
143. อย่าเพิ่ม net_read_timeout
ไม่เกี่ยวกับ Password Authenticationโดยตรง
144. อย่าเพิ่ม net_write_timeout
ไม่เกี่ยว
145. อย่าเพิ่ม max_allowed_packet
ไม่เกี่ยว
146. อย่า Clear FiveM Cache
ไม่แก้ MariaDB Credentials
147. Restart FiveMช่วยไหม
ถ้า Configเพิ่งถูกแก้:
Restart Resource/Serverตาม Wrapper Requirementอาจทำให้ Connection Stringใหม่ถูก Load
แต่ถ้าค่า Configยังผิด:
Restartกี่ครั้งก็1045
148. Restart MariaDBช่วยไหม
ไม่จำเป็นหาก Account/Passwordผิด
แก้ Account Configurationตรงจุดดีกว่า
149. Reinstall MariaDBช่วยไหม
ไม่
1045เป็น Access/Authentication Problem
150. ลบ Databaseช่วยไหม
ไม่
อันตรายและไม่เกี่ยวกับ Error
151. ลบ Userแล้วสร้างใหม่ดีไหม
ไม่ควรเป็น First Fix
เพราะ:
- Grantsอาจหาย
- Applicationsอื่นอาจใช้ Accountนั้น
- Authentication Settingsอาจซับซ้อน
152. ตรวจ Accountก่อน
ใช้:
SHOW CREATE USER ...
และ:
SHOW GRANTS ...
ก่อนทำ Destructive Account Changes.
153. ถ้าต้องเปลี่ยน Password
ใช้ MariaDB Account Management Statementที่ Versionรองรับ
เช่น ALTER USER ตาม Documentation.
154. หลังเปลี่ยน Password
Update FiveM Secret/Connection Stringทันที
155. ถ้ามีหลาย FiveM Instances
ทุก Instanceที่ใช้ Accountเดียวกันต้องได้รับ Credentialใหม่ตามที่ออกแบบไว้
156. แต่ Shared Credentialเพิ่ม Blast Radius
ระยะยาวอาจแยก Accountต่อ Environment
เช่น:
fivem_prodfivem_stagefivem_dev
157. แต่ไม่จำเป็นต้องทำตอน Productionกำลังล่ม
แก้ Incidentก่อน
แล้วค่อยปรับ Architecture
158. SSL Requirement
MariaDB Accountsสามารถมี Authentication/Security Requirementsเพิ่มเติมได้ และ Access Denied Monitoringอาจเพิ่มเมื่อ SSL/TLS Requirementไม่เป็นไปตามที่กำหนด.
159. Errorหลังเปิด REQUIRE SSL
หาก Connectorไม่ได้เชื่อมด้วย TLSตามที่ Accountกำหนด:
Authentication/Accessอาจล้ม
160. อย่าปิด SSLเพื่อให้ผ่านทันที
ตรวจ Connector TLS Configurationก่อน
161. Remote Production DB ควรรักษา Encryptionเมื่อ Architectureต้องการ
ไม่ควรลด Securityเพื่อแก้1045
162. Errorหลัง Certificate Change
อ่าน TLS Errorอื่นที่เกิดร่วมด้วย
1045อาจไม่ใช่ Errorเดียว
163. Error Timeline
ตัวอย่าง:
TLS error↓1045
ต้องแก้ TLS Requirement
ไม่ใช่ Reset Passwordอย่างเดียว
164. Plugin + TLS + Host
MariaDB Authenticationสามารถมีหลายองค์ประกอบ
จึงควรตรวจ Account Definitionแทนการเดา
165. Quick Diagnosis
Error 1045↓using password YES/NO?↓username คืออะไร?↓host คืออะไร?↓connection string ถูกไหม?↓SHOW CREATE USER↓authentication plugin↓SHOW GRANTS↓test from FiveM host↓แก้ root cause
166. ถ้า using password: NO
ตรวจ Password Configurationก่อน
167. ถ้า using password: YES
ตรวจ Passwordจริง + Account Match
168. ถ้า Hostผิด
ตรวจ User@Host/Network Source
169. ถ้า Pluginไม่ตรง
แก้ Authentication Methodให้ MariaDBและConnectorรองรับร่วมกัน
170. ถ้า Grantsไม่พอ
Grantเฉพาะ Permissionsที่ Resourceต้องใช้
171. ถ้า CLIผ่านแต่ FiveMไม่ผ่าน
Connection String/Wrapperคือ Priority
172. ถ้าทั้ง CLIและFiveMไม่ผ่าน
Account/Credentials/Pluginคือ Priority
173. ถ้า Resourceเดียวไม่ผ่าน
ตรวจ Resource-specific DB Config
174. ถ้าทุก Resourceไม่ผ่าน
ตรวจ Core DB Credential
175. FiveM MySQL Error 1045 FAQ
FiveM MySQL Error 1045 คืออะไร
MariaDB Error1045 / SQLSTATE28000 / ER_ACCESS_DENIED_ERROR คือ Access denied for user ... (using password: ...).
สาเหตุหลักคืออะไร
MariaDB Documentation ระบุ Possible Causes เช่น User/Password Combinationไม่มีอยู่ หรือ Userไม่มี Privilegesบน Databaseที่พยายามเข้าถึง.
using password: YES หมายถึง Passwordถูกไหม
ไม่ หมายถึง Connection Attemptส่ง Passwordมาเท่านั้น
using password: NO หมายถึงอะไร
Clientไม่ได้ส่ง Passwordใน Attemptนั้น
Error1045กับ1130ต่างกันอย่างไร
1130เน้น Hostไม่ได้รับอนุญาต ส่วน1045เน้น User Authentication/Access Denied.
Error1045กับ1044ต่างกันอย่างไร
MariaDB Error1044คือ Access Deniedต่อ Database ส่วน1045คือ Access Deniedของ Account Login Context.
เปลี่ยน Passwordช่วยไหม
ช่วยเมื่อ Passwordไม่ตรงจริง แต่ไม่ช่วยถ้า Account Hostหรือ Authentication Pluginผิด
MariaDB Account มี Hostด้วยหรือไม่
มี Accountถูกกำหนดเป็น User+Host และ Authentication Propertiesผูกกับ Accountนั้น.
'fivem'@'localhost' กับ 'fivem'@'10.0.0.20' เหมือนกันไหม
ไม่ใช่ Account Contextเดียวกัน
ดู Account Definitionอย่างไร
ใช้:
SHOW CREATE USER 'fivem'@'host';
MariaDBระบุว่า Statementนี้แสดง SQLที่ใช้สร้าง Userพร้อม Authentication Details.
ดูสิทธิ์อย่างไร
ใช้:
SHOW GRANTS FOR 'fivem'@'host';
เพื่อดู Grantsของ Accountนั้น.
Authentication Pluginเกี่ยวไหม
เกี่ยว MariaDBรองรับ Pluggable Authenticationและ Accountสามารถกำหนด Pluginผ่าน IDENTIFIED VIA/WITH.
mysql_native_password คืออะไร
เป็นหนึ่งใน MariaDB Authentication Pluginsที่รองรับ Password-based Authentication.
unix_socketคืออะไร
เป็น Authentication Pluginที่ใช้ Unix Socket/OS User Contextและพบได้กับ Local Accounts เช่น root@localhostใน MariaDB Installationsหลายแบบ.
FiveMควรใช้ rootไหม
ไม่ควรใช้ rootเป็นทางลัดแก้1045 ควรใช้ Dedicated Application Account
sudo mariadb เข้าได้แต่ FiveMไม่ได้ทำไม
Root Accountอาจใช้ unix_socket Authentication ซึ่งไม่เหมือน Remote/Application Password Authentication.
Errorหลังเปลี่ยน Passwordทำอย่างไร
Update Connection String/Secretของ FiveMให้ตรง Accountใหม่
Errorหลังย้าย VPSทำอย่างไร
ตรวจทั้ง User@Host, Passwordและ Source Hostใหม่
Errorหลัง MariaDB Migrationทำอย่างไร
ตรวจ Account, Host, Authentication Pluginและ Grantsบน Serverใหม่
Errorหลัง Restore Databaseทำอย่างไร
ตรวจ MariaDB Application Accountแยกจาก Gameplay Tables เพราะ Data Restoreไม่ได้รับประกันว่า Account Configurationจะตรง Environmentเดิม
Errorหลังเปลี่ยน Database Nameทำอย่างไร
ตรวจ Grantsบน Databaseใหม่ เพราะ MariaDBระบุ Database Privilegeไม่พอเป็น Possible Causeของ Access Denied.
Resourceเดียวขึ้น1045ทำไม
Resourceนั้นอาจใช้ Connection Stringหรือ Database Accountแยกจาก Core
ทุก Resourceขึ้น1045ทำไม
Core Database Wrapper/Credentialอาจผิด
CLIผ่านแต่ FiveMไม่ผ่านทำอย่างไร
ตรวจ FiveM Connection String, Environment Variablesและ Wrapper Configuration
CLIจาก FiveM Hostก็1045ทำอย่างไร
ตรวจ MariaDB Account, Password, Host, Authentication Pluginและ Grants
Testจาก Laptopแทนได้ไหม
ไม่ดีที่สุด เพราะ MariaDB Account Matchingขึ้นกับ Hostด้วย
ต้อง Restart MariaDBไหม
ไม่ใช่ First Fixของ1045
Restart FiveMช่วยไหม
ช่วย Reload Configได้ถ้าค่า Connection Stringถูกแก้แล้วและ Wrapperต้อง Restart แต่ไม่ได้แก้ Credentialที่ยังผิด
Clear FiveM Cacheช่วยไหม
ไม่
เพิ่ม max_connectionsช่วยไหม
ไม่
เพิ่ม max_connect_errorsช่วยไหม
ไม่
เพิ่ม wait_timeoutช่วยไหม
ไม่
เพิ่ม net_read_timeoutช่วยไหม
ไม่
เพิ่ม max_allowed_packetช่วยไหม
ไม่
Error1045หมายความว่าโดน Hackไหม
ไม่ Errorเดียวไม่พิสูจน์การโจมตี อาจเป็นเพียง Passwordเก่าหรือ Configผิด
1045เกิดจำนวนมากผิดปกติควรทำอะไร
ตรวจ Source Hostและ Access Denied Monitoring เพราะ MariaDBมี access_denied_errors สำหรับเหตุการณ์ที่ Login/Privileges/SSL Requirementsไม่ผ่าน.
Unknown IPพยายาม Loginควรทำอย่างไร
ตรวจ Firewall/Network Exposureและ Accounts ไม่ควร Grant Accessให้ Unknown Host
ใช้ % แก้ได้ไหม
ไม่ควรเปิด Host Scopeกว้างขึ้นเพียงเพื่อแก้1045 ถ้า FiveMมี Source Hostที่ระบุได้
ใช้ GRANT ALL ON *.* ดีไหม
ไม่ควรเป็น Default Solution ควรให้เฉพาะ Database/Privilegesที่ Applicationต้องใช้
ใช้ skip-grant-tables ได้ไหม
ไม่ควรใช้กับ Application Authentication Problemปกติ เพราะเป็นโหมด Bypass Privilege Systemสำหรับ Recoveryเฉพาะกรณี
ต้อง Reinstall MariaDBไหม
ไม่
ต้องลบ Userไหม
ไม่ควรเป็น First Fix ให้ตรวจ SHOW CREATE USER และ SHOW GRANTS ก่อน.
ต้องลบ Databaseไหม
ไม่
ต้อง Backupไหม
ก่อนเปลี่ยน Gameplay Data/Schema/Migrationควร Backupตามปกติ ส่วนการแก้ Password/User Accountควรจด Account Definitionและ Grantsไว้ก่อนเปลี่ยน
สรุป FiveM MySQL Access Denied for User Error 1045
FiveM MySQL/MariaDB Error 1045 Access denied for user เกิดเมื่อ Account ที่ FiveM ใช้ไม่ผ่าน Authentication หรือไม่มี Access ที่จำเป็น โดย MariaDB กำหนด Error นี้เป็น ER_ACCESS_DENIED_ERROR, SQLSTATE 28000 และระบุ Username/Password Combination ที่ไม่ถูกต้องหรือ Database Privileges ไม่เพียงพอเป็น Possible Causes.
จำ Flow นี้ไว้:
1045↓อ่านข้อความ user@host↓ดู using password YES/NO↓ตรวจ Connection String↓ตรวจ SHOW CREATE USER↓ตรวจ Authentication Plugin↓ตรวจ SHOW GRANTS↓ทดสอบจาก FiveM Hostจริง↓แก้ Password / Account / Plugin / Privileges
สิ่งที่ comsiam แนะนำคืออย่าเห็น 1045 แล้ว Reset Password หรือสร้าง 'fivem'@'%' ทันที เพราะ MariaDB Account ผูกทั้ง Username, Host และ Authentication Method การแก้ Password ให้ Account ผิด Hostจะไม่ช่วยอะไร และการเปิด Hostกว้างเกินจำเป็นเพียงเพิ่มความเสี่ยง ควรใช้ SHOW CREATE USER กับ SHOW GRANTS เพื่อดู Accountที่มีอยู่จริงก่อนเปลี่ยน Configuration.
อีกหลักที่ comsiam แนะนำคือถ้า Command-line Testจาก FiveM Hostด้วย Accountเดียวกันผ่าน แต่ FiveMยังขึ้น1045 ให้หยุดแก้ MariaDBแล้วกลับไปตรวจ Connection String, Environment Variableและ Database Wrapper เพราะ MariaDB Accountทำงานได้แล้ว แต่ Applicationอาจยังใช้ Username, Password, Hostหรือ Databaseคนละค่ากับที่ทดสอบ วิธีนี้จะลดการแก้ User/Privilegesเกินความจำเป็นและรักษาความปลอดภัยของ Production Databaseไว้ได้
Comments
Post a Comment