FiveM MySQL Access Denied for User Error 1045 แก้อย่างไร? ตรวจ Username, Password, User@Host และ Authentication Plugin ให้ถูกจุด

ปัญหา FiveM MySQL/MariaDB ขึ้น Access denied for user หรือ Error 1045 หมายความว่า FiveM สามารถติดต่อ MariaDB ได้ถึงขั้น Authentication แล้ว แต่ Database ไม่ยอมให้ Account นั้นเข้าสู่ระบบตามข้อมูลหรือสิทธิ์ที่กำหนดไว้

MariaDB กำหนด Error 1045, SQLSTATE 28000 เป็น:

ER_ACCESS_DENIED_ERROR
Access denied for user '%s'@'%s' (using password: %s)

และเอกสาร MariaDB ระบุสาเหตุสำคัญ เช่น Username/Password Combination ไม่มีอยู่ หรือ User ไม่มีสิทธิ์สำหรับ Database ที่กำลังพยายามเข้าถึง.

ตัวอย่าง:

ERROR 1045 (28000):
Access denied for user 'fivem'@'10.0.0.20'
(using password: YES)

สำหรับ FiveM ปัญหานี้มักเกิดหลัง:

  • เปลี่ยนรหัส Database
  • ย้าย VPS
  • ย้าย MariaDB
  • Clone Server
  • แก้ server.cfg
  • เปลี่ยน Connection String
  • เปลี่ยน Database User
  • Restore Database แต่ไม่ได้ Restore Account/Privileges
  • เปลี่ยน Authentication Plugin
  • ใช้ User ถูกชื่อแต่ Host ไม่ตรง
  • Production/Test Config สลับกัน
  • Password มีอักขระพิเศษแล้ว Connection String Parse ผิด
  • Resource ใช้ Database Credential คนละชุดกับ Core Server

หลักการแก้ที่ถูกต้องคือ:

อ่าน Error 1045 ให้ครบ
↓
ดู username@host
↓
ดู using password YES/NO
↓
ตรวจ Connection String
↓
ตรวจ Account ที่ MariaDB มีจริง
↓
ตรวจ Authentication Plugin
↓
ตรวจ SHOW GRANTS
↓
ทดสอบจาก FiveM Host จริง
↓
แก้เฉพาะ Root Cause

① FiveM MySQL Error 1045 คืออะไร

MariaDB Error 1045 คือ:

1045
28000
ER_ACCESS_DENIED_ERROR

พร้อมข้อความ:

Access denied for user 'user'@'host'
(using password: YES/NO)

MariaDB Documentation จัด Error นี้เป็น Authentication/Access Error โดยตรง.

② Error นี้ต่างจาก Error 1130 อย่างไร

หัวข้อก่อนหน้า Error 1130 คือ:

Host is not allowed to connect

เน้นว่า Host ไม่มี Account ที่ได้รับอนุญาตให้เชื่อมเข้ามา

ส่วน 1045 คือ:

Access denied for user

แปลว่าการเชื่อมต่อมาถึงขั้นที่ MariaDB พยายาม Authenticate Account แล้วแต่ไม่ผ่าน.

③ จำง่าย ๆ

1130 = Host ไม่ผ่าน
1045 = User/Authentication ไม่ผ่าน

④ ต่างจาก Error 1044 อย่างไร

MariaDB Error Code Reference แยก:

1044 = Access denied for user ... to database ...
1045 = Access denied for user ... (using password ...)

ดังนั้น 1044 จะเน้นการเข้าถึง Database ที่ระบุ ส่วน 1045 เน้น Authentication/Account Access มากกว่า.

⑤ Error 1045 เป็น SQL Syntax Error หรือไม่

ไม่

SQL Syntax Error ทั่วไปคือ 1064

1045 เกิดก่อน Gameplay Query จะทำงานตามปกติ เพราะ Connection Authentication ไม่ผ่าน

⑥ using password: YES หมายความว่าอะไร

หมายความว่า Client Attempt นั้นส่งข้อมูล Password มาในการ Authentication

ไม่ได้แปลว่า Password ที่ส่งมานั้นถูก

⑦ using password: NO หมายความว่าอะไร

หมายความว่า Connection Attempt นั้นไม่ได้ส่ง Password ในรูปแบบที่ Error Report รับรู้

ถ้า Account ต้องใช้ Password:

นี่เป็นเบาะแสสำคัญ

⑧ อย่าสับสน YES กับ “Password ถูก”

ตัวอย่าง:

Access denied ...
(using password: YES)

แปลเพียง:

มี password ถูกส่งมา

ไม่ใช่:

password ถูกต้อง

⑨ สาเหตุที่พบบ่อยที่สุด — Password ผิด

เช่น Database Password จริงคือ:

NewPassword

แต่ FiveM ยังใช้:

OldPassword

Connection จะถูกปฏิเสธ

⑩ Error หลังเปลี่ยน Database Password

นี่เป็น Pattern ที่ตรงมาก

Flow:

MariaDB password changed
↓
FiveM config ยังเป็น password เก่า
↓
resource reconnect
↓
1045 Access denied

⑪ ต้องตรวจ Connection String

ดูค่าที่ FiveM ใช้จริง เช่น:

host
port
database
username
password

⑫ อย่าโพสต์ Connection String เต็มต่อสาธารณะ

โดยเฉพาะ:

password

ต้อง Mask ก่อนแชร์ Logs

⑬ Password Copy/Paste ผิดได้

เช่นมี:

  • Space นำหน้า
  • Space ท้าย
  • Newline
  • Character หาย

จึงควรตรวจค่าอย่างระมัดระวัง

⑭ Password มีอักขระพิเศษ

ถ้า Connection String ใช้ URI-style Syntax:

อักขระบางตัวอาจมีความหมายพิเศษใน URI/Connector

จึงควรใช้ Encoding หรือ Connection Format ตาม Database Wrapper ที่ FiveM ใช้อยู่จริง

⑮ อย่าเปลี่ยน Password ให้เป็น 1234 เพื่อทดลอง Production

ลด Security โดยไม่จำเป็น

หากสงสัย Parsing:

ใช้วิธี Config/Encoding ที่ Wrapper รองรับ

⑯ Username ผิดก็ทำ 1045 ได้

ตัวอย่าง:

Database Account จริง:

fivem_prod

แต่ Config:

fivem

MariaDB สามารถ Reject ได้

⑰ Error Message บอก Username ที่ถูกใช้จริง

เช่น:

Access denied for user 'fivem_test'@'10.0.0.20'

นี่เป็นข้อมูลสำคัญมาก

เพราะแสดงว่า FiveM กำลังใช้:

fivem_test

ไม่ใช่ Account ที่คุณคิด

⑱ ตรวจ Config หลายจุด

FiveM Server บางตัวอาจมี Connection Settings มากกว่า 1 แห่ง เช่น:

  • Core DB
  • Phone DB
  • Logs DB
  • External API

⑲ Resource เดียว Error 1045

ถ้า:

inventory ปกติ
garage ปกติ
bank ปกติ
phone error 1045

Phone Resource อาจใช้ Database Credential แยก

⑳ ทุก Resource Error 1045

มีโอกาสสูงว่า Core Database Connection/Wrapper ใช้ Account ผิด

㉑ MariaDB Account ไม่ได้มีแค่ Username

MariaDB Account ใช้รูปแบบ:

'user'@'host'

และ Authentication Configuration ผูกกับ Account นั้น.

㉒ ตัวอย่าง

'fivem'@'localhost'

กับ:

'fivem'@'10.0.0.20'

เป็นคนละ Account Context

㉓ Password เดียวกันก็ไม่ได้แปลว่าใช้แทนกันได้

ถ้า Host Matching เลือก Account คนละตัว:

Authentication Configuration และ Privileges อาจต่างกัน

㉔ Error หลังย้าย FiveM VPS

เดิม FiveM มาจาก:

10.0.0.10

ใหม่มาจาก:

10.0.0.20

Account ที่ MariaDB Match อาจเปลี่ยน

㉕ หาก Host ไม่ได้รับอนุญาตเลย

อาจเจอ 1130 มากกว่า

แต่ถ้า Account Matching มาถึง Authentication แล้วข้อมูลไม่ถูกต้อง:

อาจเจอ 1045

㉖ อย่าดู Username อย่างเดียว

อ่านข้อความเต็ม:

'user'@'host'

เสมอ

㉗ SHOW CREATE USER มีประโยชน์มาก

MariaDB มี:

SHOW CREATE USER 'user'@'host';

เพื่อแสดง SQL ที่สามารถสร้าง Account เดิมกลับมา รวมถึง Authentication Details.

㉘ ตัวอย่าง

SHOW CREATE USER 'fivem'@'10.0.0.20';

ใช้ Account จริงของ Server

㉙ ทำไมต้องดู SHOW CREATE USER

เพราะช่วยตรวจ:

  • Authentication Plugin
  • Account Definition
  • Authentication Configuration

โดยไม่ต้องเดา

㉚ Authentication Plugin คืออะไร

MariaDB รองรับระบบ Authentication แบบ Plugin และ Account สามารถกำหนด Plugin ที่ใช้ Authenticate ได้ผ่าน CREATE USER ... IDENTIFIED VIA/WITH ....

㉛ FiveM ต้องสนใจ Plugin ไหม

ถ้า Account ใช้ Authentication Plugin ที่ Database Connector ของ FiveM ไม่รองรับหรือ Config ไม่ตรง:

Authentication อาจล้มเหลว

㉜ MariaDB รองรับหลาย Authentication Plugins

เอกสาร MariaDB ระบุว่า Account สามารถผูกกับ Authentication Plugins และในรุ่นใหม่สามารถกำหนดหลาย Plugin ให้ Account ได้ด้วย.

㉝ อย่าเปลี่ยน Authentication Plugin แบบสุ่ม

เช่นเห็น 1045แล้วเปลี่ยนทุก Userเป็น:

mysql_native_password

ทันที

ต้องตรวจ:

  • MariaDB version
  • Wrapper support
  • Account ที่กำลังใช้

ก่อน

㉞ mysql_native_password

MariaDB มี Authentication Plugin นี้และเอกสารอธิบายการสร้าง Account/Password สำหรับ Plugin โดยตรง.

㉟ แต่ไม่ใช่ Plugin เดียว

MariaDB มี Plugin อื่น เช่น:

  • unix_socket
  • PAM
  • ed25519
  • GSSAPI

ตาม Environment.

㊱ FiveM Application Account ควรใช้ Plugin ไหน

ไม่มีคำตอบสากลโดยไม่รู้ Database Connector ที่ FiveM ใช้

ควรใช้ Authentication Method ที่:

  • MariaDB รองรับ
  • Database Wrapper รองรับ
  • Security Policy อนุญาต

㊲ Root Account อาจใช้ unix_socket

MariaDB Documentation ปัจจุบันระบุว่า root@localhost ที่สร้างโดย mariadb-install-db สามารถถูกตั้งให้ใช้ unix_socket Authentication ได้ในหลาย Installation.

㊳ ทำไม sudo mariadb เข้าได้แต่ใช้ Password ไม่ได้

อาจเป็นเพราะ Root Account ใช้ unix_socket

ไม่ได้หมายความว่า Password ของ Application ใช้งานได้

㊴ FiveM ไม่ควรใช้ root เพราะเหตุนี้

FiveM Application ควรมี Dedicated MariaDB Account

ไม่ควรใช้ root เพื่อหลีกเลี่ยง Authentication Problem

㊵ unix_socket เหมาะกับ Remote FiveM ไหม

โดยธรรมชาติ Plugin นี้อาศัย Unix Socket/OS User Context บน Host เดียวกัน จึงไม่ได้ออกแบบเป็น Remote Password Authentication ทั่วไป.

㊶ ดังนั้น Dedicated Application Account สำคัญ

เช่น:

fivem application
↓
dedicated DB user
↓
supported auth plugin
↓
required privileges only

㊷ ตรวจ Account ด้วย SHOW CREATE USER

ตัวอย่าง:

SHOW CREATE USER 'fivem'@'10.0.0.20';

ถ้า Plugin ไม่ตรงกับ Connector Requirement:

แก้ Account ตาม Documentation ของ MariaDB/Wrapper

㊸ อย่า UPDATE ตาราง mysql.user ตรง ๆ

ใช้ Account Management Statements เช่น:

  • CREATE USER
  • ALTER USER
  • SET PASSWORD
  • GRANT

ตาม Version ที่รองรับ

㊹ ALTER USER

MariaDB มี ALTER USER สำหรับเปลี่ยน Authentication Properties ของ Account.

㊺ แต่ก่อน ALTER

ต้อง Backup/จด Account Definition ไว้

เช่นใช้:

SHOW CREATE USER ...

เพื่อมี Reference

㊻ Error หลัง MariaDB Upgrade

Authentication Behavior/Plugins อาจต่างจาก Environment เดิม

จึงควรตรวจ:

SHOW CREATE USER ...

หลัง Upgrade

㊼ Error หลัง Restore Database

สิ่งสำคัญคือ Application Tables กับ MariaDB Accounts เป็นคนละส่วนของระบบ

การ Restore Gameplay Database ไม่ได้หมายความว่า Application Account/Authentication จะถูก Restore ตามแบบที่ต้องการเสมอไป

㊽ Server Migration Checklist

ควรตรวจ:

Database data
Database user
User@Host
Password
Authentication plugin
Grants
Firewall
Connection string

㊾ Error หลัง Clone Production

Clone Config อาจยังใช้:

production user

กับ Test Server

㊿ Production MariaDB อาจ Reject Host ใหม่

หรือ Test Server อาจเข้าถึง Production โดยไม่ตั้งใจ

ดังนั้นอย่าแก้ด้วยการเปิดกว้างทันที

51. Test Database ควรแยก

ถ้าเป็นไปได้

ลดความเสี่ยงจาก:

  • Resource Migration
  • DELETE
  • Schema Changes
  • Test Transactions

52. Error 1045 อาจช่วยป้องกัน Production

ถ้า Test Host ไม่ควรเข้า Production DB แล้วถูก Reject:

อย่ารีบ Grant Access ก่อนตรวจ Architecture

53. Error หลังแก้ Password แล้วไม่หาย

ตรวจ User@Host

เพราะอาจแก้ Password ให้ Account:

'fivem'@'localhost'

แต่ FiveM กำลัง Match:

'fivem'@'10.0.0.20'

54. Account คนละตัว

การเปลี่ยน Password ตัวหนึ่งไม่ได้เปลี่ยนอีกตัว

55. SHOW CREATE USER ทั้งสอง Account

ช่วยให้เห็นความแตกต่าง

56. SHOW GRANTS ใช้ทำอะไร

MariaDB SHOW GRANTS แสดง Privileges ที่กำหนดให้ Account นั้น.

ตัวอย่าง:

SHOW GRANTS FOR 'fivem'@'10.0.0.20';

57. Error1045กับ Privilegesเกี่ยวไหม

MariaDB Error 1045 Documentation ระบุ Possible Cause รวมถึง User ไม่มี Privilege บน Database ที่พยายามเข้าถึง.

ดังนั้นหาก Credentials ถูก:

ต้องตรวจ Grants ด้วย

58. แต่ Login ไม่ผ่านตั้งแต่แรก

ให้เริ่มจาก:

  • Account
  • Host
  • Password
  • Plugin

ก่อน

59. ถ้า Login ผ่านแต่ USE database ไม่ได้

MariaDB Connection Troubleshooting Guide ระบุว่าหาก User เชื่อมได้แต่ไม่มีสิทธิ์ Database นั้น ให้ Grant Privileges ที่จำเป็นบน Database ให้ Account.

60. Error อาจเปลี่ยนหลังแก้ Authentication

เช่น:

1045

หายแล้วกลายเป็น:

command denied

นี่อาจหมายถึง Connectionผ่านแล้วแต่ Privilegesยังไม่พอ

61. ไม่ควร Grant ALL ON *.*

เพียงเพราะต้องการให้ Error หาย

62. Principle ที่ดีกว่า

ให้ Application Account เข้าถึงเฉพาะ:

Database ที่ FiveM ใช้

และ Privileges เท่าที่ Resource ต้องใช้

63. FiveM Runtime มักต้องทำอะไร

ขึ้นกับ Framework/Resources แต่โดยทั่วไปอาจมี:

  • SELECT
  • INSERT
  • UPDATE
  • DELETE

ส่วน Schema Migrations บาง Resource อาจต้อง Permissions เพิ่ม

64. อย่าเดา Permission Set

อ่าน Resource Documentation

65. Runtime Account กับ Migration Account

ระบบที่เข้มขึ้นสามารถแยกสองบทบาทได้

แต่ไม่จำเป็นต้องทำทันทีในทุก FiveM Server

66. Error หลัง Resource Auto Migration

ถ้า Authentication ผ่านแต่ Migrationไม่มี Privilege:

Error จะเป็น Permission/DDL Error มากกว่า 1045

อ่าน Consoleต่อไป

67. CURRENT_USER() มีประโยชน์หลัง Connect ได้

MariaDB CURRENT_USER() แสดง Account User/Host ที่ Server ใช้ Authenticate Session จริง.

ใช้:

SELECT CURRENT_USER();

68. ทำไมมีประโยชน์

คุณอาจคิดว่า MariaDBใช้:

'fivem'@'%'

แต่จริง ๆ Match Accountเฉพาะกว่าอีกตัว

69. USER() กับ CURRENT_USER() อาจต่างกัน

ในการวิเคราะห์ Account Matching สิ่งสำคัญคือ Account ที่ MariaDB ใช้ Authenticate จริง

70. แต่ถ้า Error1045ยังอยู่

ยัง Query CURRENT_USER() จาก Connection นั้นไม่ได้

ต้องใช้ Admin Session ตรวจ Accountก่อน

71. SHOW CREATE USER มีความแม่นกว่าเดา Config

เพราะแสดง Account Definitionจาก MariaDBจริง.

72. Errorหลัง Server Restart

ถ้า Database Passwordถูกเปลี่ยนแบบ Runtime/Configไม่สอดคล้อง:

อาจเพิ่งแสดงผลหลัง Restart

73. Errorก่อน Restartไม่เกิด

แต่หลัง Restartเกิด:

ตรวจว่า MariaDB โหลด Account/Plugin/Config ตามที่คาดหรือไม่

74. FiveM Connection Stringก็อาจ Loadใหม่หลัง Restart

ถ้าเดิม Processยังใช้ค่าเก่าใน Memory

Restart Resourceแล้วอาจใช้ค่า Configใหม่ที่ผิด

75. Errorหลังแก้ server.cfg

ย้อนดู Diff

โดยเฉพาะ Connection String

76. Quotes ใน Config

ตรวจ:

  • quote เปิด/ปิด
  • whitespace
  • special characters

ตาม Syntaxของ Wrapper

77. อย่าใช้ Syntax จาก Wrapper คนละตัว

ตัวอย่าง Optionsของ Database Clientหนึ่ง:

อาจไม่รองรับในอีกตัว

78. FiveM Database Wrapper Version สำคัญ

Connection String Format หรือ Connector Support อาจเปลี่ยนตาม Version

ใช้ Official Docsของ Wrapperนั้น

79. Errorหลังย้ายจาก mysql-async ไป oxmysql หรือ Database Wrapper ใหม่

ตรวจ:

  • connection string format
  • supported authentication
  • resource compatibility

80. อย่ารัน Wrappersหลายตัวเพียงเพื่อแก้1045

1045เป็น Authentication Issue

เพิ่ม Wrapperอีกตัวไม่ได้ทำ Password/Userถูกขึ้นมา

81. Error using password: NO

ตรวจว่า Connection String มี Password field จริงหรือไม่

82. Environment Variable ว่าง

ตัวอย่าง:

DB_PASSWORD=

อาจทำให้ Clientส่งไม่มี Password

83. Secret Manager/Panel

หาก Passwordถูกเก็บผ่าน Hosting Panel:

ตรวจว่าค่า Environmentถูกส่งเข้า FiveM Processจริง

84. Docker Compose

Environment Variable Nameผิดหนึ่งตัว:

Applicationอาจใช้ค่า Empty

85. แต่ไม่ควร Print Secretทั้งหมดเพื่อ Debug

แสดงเพียง:

password loaded = yes/no

ใน Developmentอย่างปลอดภัยก็เพียงพอ

86. Error using password: YES

ตรวจว่า Passwordตรง Accountที่ Matchหรือไม่

87. Password ของ Account Host-specific

Account:

'fivem'@'localhost'

กับ:

'fivem'@'%'

อาจตั้ง Passwordไม่เหมือนกัน

88. จึงต้องรู้ Accountที่ Matchจริง

ไม่ใช่ Resetทุก Accountชื่อ fivem

89. อย่า Reset Passwordหลาย Accountsพร้อมกัน

อาจทำ Applicationsอื่นใช้งานไม่ได้

90. แยก User ต่อ Application

ช่วยลดความสับสน เช่น:

fivem_app
website_app
backup_app

91. ช่วย Securityด้วย

เพราะแต่ละ Applicationสามารถมี Privilegesต่างกัน

92. Errorหลัง Website Password Change

ถ้า FiveMใช้ Userเดียวกับ Website:

การเปลี่ยน Password Websiteอาจทำ FiveMเสียด้วย

นี่เป็นอีกเหตุผลให้แยก Application Accounts

93. Shared Database User ไม่ผิดเสมอไป

แต่เพิ่ม Coupling และทำ Troubleshootingยากขึ้น

94. Errorหลัง Hosting Provider Reset DB Password

FiveM Connection String ต้อง Updateให้ตรง

95. Errorหลัง Import User Tableจาก Serverเก่า

ไม่ควร Copy System Account Tablesข้าม Versionแบบสุ่ม

ใช้ MariaDB Migration/Account-management วิธีที่เหมาะสมกว่า

96. Authentication Plugin Compatibility

MariaDB Pluggable Authentication Documentation ระบุว่า Accountสามารถกำหนด Authentication Pluginผ่าน IDENTIFIED VIA/WITH และ Pluginต้องติดตั้ง/Activeบน Server.

97. Pluginไม่มี

Authenticationอาจไม่ทำงานตามที่ Accountถูกกำหนด

98. ตรวจ Plugin

Adminสามารถตรวจ Active Pluginsตาม MariaDB Documentation

แต่ไม่ควร INSTALL Pluginเพียงเพราะ1045โดยไม่มีหลักฐาน

99. Errorหลังเปลี่ยน Plugin

ถ้า:

ก่อน = ทำงาน
หลัง ALTER USER plugin = 1045

Rollback/แก้ตาม MariaDB Documentationและ Connector Support

100. MariaDB 10.4+ Authentication

MariaDB Documentation อธิบายว่า Account Authentication Model สามารถใช้หลาย Authentication Methods ใน Accountเดียวได้ใน Versionsใหม่.

101. นี่ทำให้ Account Diagnosisซับซ้อนขึ้น

จึงควรดู:

SHOW CREATE USER ...

แทน Guess

102. Errorหลังเปลี่ยน root Password

FiveMไม่ควรใช้ rootตั้งแต่แรก

ถ้าใช้:

ควรย้ายไป Dedicated Application Accountอย่างเหมาะสม

103. ห้ามใช้ skip-grant-tables เพื่อแก้ 1045 ปกติ

มัน Bypass Authentication/Privilege Checks และเหมาะกับ Recovery Scenariosเฉพาะ ไม่ใช่ Application Fix

104. อย่าปิด Authenticationทั้งระบบ

เพียงเพื่อให้ FiveMเชื่อมได้

105. Error1045ไม่ใช่เหตุผลเปิด Database Public

FirewallและAuthenticationเป็น Security Layersคนละส่วน

106. Remote Database

ถ้า FiveMกับMariaDBคนละเครื่อง:

ต้องตรวจ:

FiveM source host
MariaDB account host
credentials

ร่วมกัน

107. ถ้า Firewall Block

มักจะได้ Connection Timeout/Refused มากกว่า 1045

เพราะ Connectionยังไปไม่ถึง Authentication

108. ดังนั้น 1045เป็นสัญญาณว่าการเชื่อมไปถึง MariaDBในระดับ Authenticationแล้ว

จึงไม่ควรเริ่มด้วยการเปิด Firewallกว้างขึ้น

109. Errorหลังเปลี่ยน IP FiveM

Account Matchingอาจเปลี่ยน

ตรวจ User@Hostก่อน Reset Password

110. NAT

MariaDBอาจเห็น Source Hostที่ต่างจาก IPใน FiveM Machine

111. VPN

เช่นเดียวกัน

การเปิด/ปิด VPNอาจเปลี่ยน Hostที่ MariaDBเห็น

112. Docker

Container Networkอาจทำให้ Host Matchingต่างจาก Public IP

113. Cloud Private Network

อาจเห็น Private IPเป็น Source

นี่เป็นสาเหตุที่ควรอ่านข้อความ:

'user'@'host'

จาก Errorจริง

114. อย่า Mask Hostจนตัวเอง Debugไม่ได้

แชร์ Publicค่อย Maskบางส่วน

แต่ในการตรวจภายในต้องรู้ Sourceจริง

115. Password ถูกแต่ยัง 1045

Checklist:

Account ชื่อถูก?
Host ถูก?
Authentication plugin ถูก?
Database privilege ถูก?
Connection String ชี้ server ถูก?

116. Connection String ชี้ DB คนละ Server

เกิดได้หลัง Migration

คุณอาจ Reset Passwordบน:

db-new

แต่ FiveMยังเชื่อม:

db-old

จึงยัง1045

117. ทดสอบด้วย MariaDB Client จาก FiveM Host

นี่เป็นวิธีแยก:

Database account problem

ออกจาก:

FiveM wrapper config problem

118. ถ้า CLIจาก FiveM Hostก็1045

ปัญหาอยู่ที่ Account/Credentials/Authenticationเป็นหลัก

119. ถ้า CLIผ่านแต่ FiveM1045

ตรวจ FiveM Connection String/Wrapper

120. ใช้ Credentialเดียวกันในการ Test

แต่ทำอย่างปลอดภัย

อย่าใส่ Passwordใน Shell Historyถ้า Toolมีวิธี Prompt Password

121. Test จาก Laptopไม่พอ

เพราะ:

'user'@'laptop-host'

อาจ Match Accountคนละตัวกับ:

'user'@'fivem-host'

122. ต้อง Test จาก Hostเดียวกับ FiveM

เพื่อให้ Account Matchingใกล้เคียง Productionจริง

123. SHOW GRANTS

หลังรู้ Accountที่ Matchแล้ว:

ตรวจ:

SHOW GRANTS FOR 'fivem'@'host';

MariaDB Connection Troubleshooting Guide ระบุว่าหาก Userไม่มีสิทธิ์ Databaseให้ Grant Privilegesที่จำเป็น.

124. อย่าดู Grantsของ Accountผิด Host

เช่นดู:

'fivem'@'localhost'

แต่ FiveMใช้:

'fivem'@'10.0.0.20'

จะทำให้วิเคราะห์ผิด

125. Errorหลังสร้าง Userแต่ลืม Grant

Connectionอาจ Authenticationผ่านบางขั้นแต่เข้า Databaseที่ระบุไม่ได้

126. Database ใน Connection String

ถ้า Connection Stringระบุ Databaseที่ Accountไม่มีสิทธิ์:

MariaDB Error1045 Documentationระบุ Privilegeบน Databaseเป็น Possible Cause.

127. ทดลองเชื่อมโดยไม่ระบุ Database

ใน Troubleshooting Environmentที่ปลอดภัยอาจช่วยแยกว่า:

  • Authenticationผ่านหรือไม่
  • Database-specific privilegeเป็นปัญหาหรือไม่

ใช้ตาม MariaDB Client/Environment

128. แต่ FiveM Productionต้องใช้ Databaseจริง

สุดท้าย Privilegesต้องถูกต้อง

129. Errorหลังเปลี่ยน Database Name

เช่น:

fivem_old

→

fivem_prod

Userเดิมอาจไม่มี Grantsบน Databaseใหม่

130. GRANTใหม่ต้องระบุ Databaseถูก

อย่าพิมพ์ชื่อผิด

131. Underscore/Wildcard ใน GRANT

การอ้าง Database Namesใน Privilege Statementsต้องใช้ Syntaxให้ถูกต้อง

โดยเฉพาะชื่อที่มี Characterพิเศษ

132. SHOW GRANTSช่วยตรวจสิ่งที่ Serverใช้จริง

ดีกว่าดู Script Migrationอย่างเดียว

133. access_denied_errors

MariaDB มี Status/Monitoringเกี่ยวกับ Access Denied Events และเอกสารระบุว่า Failed Logins, Invalid Privileges หรือ SSL Requirementที่ไม่ผ่านสามารถทำ Access Denied Countersเพิ่มได้.

134. นี่มีประโยชน์ด้าน Security Monitoring

ถ้า1045เกิดจำนวนมาก:

ต้องแยกว่าเป็น:

  • Configผิด
  • Resource Retry
  • Unknown Login Attempts

135. 1045 จำนวนมากไม่ได้แปลว่าโดน Hackทันที

Applicationที่ใช้ Passwordเก่าก็สร้าง1045เป็นพันครั้งได้

136. ดู Source Host

ถ้ามาจาก FiveM VPSหลังเปลี่ยน Password:

Root Causeมีเหตุผลชัด

137. ถ้ามาจาก Unknown Internet Hosts

และ Databaseเปิด Public:

ควรตรวจ Network Exposure/Security

138. แต่ไม่ควรตอบด้วยเปลี่ยน Portอย่างเดียว

Securityต้องดู:

  • Firewall
  • Host ACL
  • Accounts
  • Password
  • TLS

ตาม Architecture

139. Retry Storm

ถ้า FiveM Wrapper Authentication Failแล้ว Retryรัว:

Error Logอาจเต็มด้วย1045

140. อย่าแก้ด้วยเพิ่ม max_connect_errors

1045เป็น Authentication Failure

และการเพิ่ม Connection Error Thresholdไม่ได้ทำ Credentialsถูก

141. อย่าเพิ่ม max_connections

เช่นเดียวกัน

1045ไม่ได้เกิดจาก Connection Slotsเต็ม

142. อย่าเพิ่ม wait_timeout

ไม่เกี่ยว

143. อย่าเพิ่ม net_read_timeout

ไม่เกี่ยวกับ Password Authenticationโดยตรง

144. อย่าเพิ่ม net_write_timeout

ไม่เกี่ยว

145. อย่าเพิ่ม max_allowed_packet

ไม่เกี่ยว

146. อย่า Clear FiveM Cache

ไม่แก้ MariaDB Credentials

147. Restart FiveMช่วยไหม

ถ้า Configเพิ่งถูกแก้:

Restart Resource/Serverตาม Wrapper Requirementอาจทำให้ Connection Stringใหม่ถูก Load

แต่ถ้าค่า Configยังผิด:

Restartกี่ครั้งก็1045

148. Restart MariaDBช่วยไหม

ไม่จำเป็นหาก Account/Passwordผิด

แก้ Account Configurationตรงจุดดีกว่า

149. Reinstall MariaDBช่วยไหม

ไม่

1045เป็น Access/Authentication Problem

150. ลบ Databaseช่วยไหม

ไม่

อันตรายและไม่เกี่ยวกับ Error

151. ลบ Userแล้วสร้างใหม่ดีไหม

ไม่ควรเป็น First Fix

เพราะ:

  • Grantsอาจหาย
  • Applicationsอื่นอาจใช้ Accountนั้น
  • Authentication Settingsอาจซับซ้อน

152. ตรวจ Accountก่อน

ใช้:

SHOW CREATE USER ...

และ:

SHOW GRANTS ...

ก่อนทำ Destructive Account Changes.

153. ถ้าต้องเปลี่ยน Password

ใช้ MariaDB Account Management Statementที่ Versionรองรับ

เช่น ALTER USER ตาม Documentation.

154. หลังเปลี่ยน Password

Update FiveM Secret/Connection Stringทันที

155. ถ้ามีหลาย FiveM Instances

ทุก Instanceที่ใช้ Accountเดียวกันต้องได้รับ Credentialใหม่ตามที่ออกแบบไว้

156. แต่ Shared Credentialเพิ่ม Blast Radius

ระยะยาวอาจแยก Accountต่อ Environment

เช่น:

fivem_prod
fivem_stage
fivem_dev

157. แต่ไม่จำเป็นต้องทำตอน Productionกำลังล่ม

แก้ Incidentก่อน

แล้วค่อยปรับ Architecture

158. SSL Requirement

MariaDB Accountsสามารถมี Authentication/Security Requirementsเพิ่มเติมได้ และ Access Denied Monitoringอาจเพิ่มเมื่อ SSL/TLS Requirementไม่เป็นไปตามที่กำหนด.

159. Errorหลังเปิด REQUIRE SSL

หาก Connectorไม่ได้เชื่อมด้วย TLSตามที่ Accountกำหนด:

Authentication/Accessอาจล้ม

160. อย่าปิด SSLเพื่อให้ผ่านทันที

ตรวจ Connector TLS Configurationก่อน

161. Remote Production DB ควรรักษา Encryptionเมื่อ Architectureต้องการ

ไม่ควรลด Securityเพื่อแก้1045

162. Errorหลัง Certificate Change

อ่าน TLS Errorอื่นที่เกิดร่วมด้วย

1045อาจไม่ใช่ Errorเดียว

163. Error Timeline

ตัวอย่าง:

TLS error
↓
1045

ต้องแก้ TLS Requirement

ไม่ใช่ Reset Passwordอย่างเดียว

164. Plugin + TLS + Host

MariaDB Authenticationสามารถมีหลายองค์ประกอบ

จึงควรตรวจ Account Definitionแทนการเดา

165. Quick Diagnosis

Error 1045
↓
using password YES/NO?
↓
username คืออะไร?
↓
host คืออะไร?
↓
connection string ถูกไหม?
↓
SHOW CREATE USER
↓
authentication plugin
↓
SHOW GRANTS
↓
test from FiveM host
↓
แก้ root cause

166. ถ้า using password: NO

ตรวจ Password Configurationก่อน

167. ถ้า using password: YES

ตรวจ Passwordจริง + Account Match

168. ถ้า Hostผิด

ตรวจ User@Host/Network Source

169. ถ้า Pluginไม่ตรง

แก้ Authentication Methodให้ MariaDBและConnectorรองรับร่วมกัน

170. ถ้า Grantsไม่พอ

Grantเฉพาะ Permissionsที่ Resourceต้องใช้

171. ถ้า CLIผ่านแต่ FiveMไม่ผ่าน

Connection String/Wrapperคือ Priority

172. ถ้าทั้ง CLIและFiveMไม่ผ่าน

Account/Credentials/Pluginคือ Priority

173. ถ้า Resourceเดียวไม่ผ่าน

ตรวจ Resource-specific DB Config

174. ถ้าทุก Resourceไม่ผ่าน

ตรวจ Core DB Credential

175. FiveM MySQL Error 1045 FAQ

FiveM MySQL Error 1045 คืออะไร

MariaDB Error1045 / SQLSTATE28000 / ER_ACCESS_DENIED_ERROR คือ Access denied for user ... (using password: ...).

สาเหตุหลักคืออะไร

MariaDB Documentation ระบุ Possible Causes เช่น User/Password Combinationไม่มีอยู่ หรือ Userไม่มี Privilegesบน Databaseที่พยายามเข้าถึง.

using password: YES หมายถึง Passwordถูกไหม

ไม่ หมายถึง Connection Attemptส่ง Passwordมาเท่านั้น

using password: NO หมายถึงอะไร

Clientไม่ได้ส่ง Passwordใน Attemptนั้น

Error1045กับ1130ต่างกันอย่างไร

1130เน้น Hostไม่ได้รับอนุญาต ส่วน1045เน้น User Authentication/Access Denied.

Error1045กับ1044ต่างกันอย่างไร

MariaDB Error1044คือ Access Deniedต่อ Database ส่วน1045คือ Access Deniedของ Account Login Context.

เปลี่ยน Passwordช่วยไหม

ช่วยเมื่อ Passwordไม่ตรงจริง แต่ไม่ช่วยถ้า Account Hostหรือ Authentication Pluginผิด

MariaDB Account มี Hostด้วยหรือไม่

มี Accountถูกกำหนดเป็น User+Host และ Authentication Propertiesผูกกับ Accountนั้น.

'fivem'@'localhost' กับ 'fivem'@'10.0.0.20' เหมือนกันไหม

ไม่ใช่ Account Contextเดียวกัน

ดู Account Definitionอย่างไร

ใช้:

SHOW CREATE USER 'fivem'@'host';

MariaDBระบุว่า Statementนี้แสดง SQLที่ใช้สร้าง Userพร้อม Authentication Details.

ดูสิทธิ์อย่างไร

ใช้:

SHOW GRANTS FOR 'fivem'@'host';

เพื่อดู Grantsของ Accountนั้น.

Authentication Pluginเกี่ยวไหม

เกี่ยว MariaDBรองรับ Pluggable Authenticationและ Accountสามารถกำหนด Pluginผ่าน IDENTIFIED VIA/WITH.

mysql_native_password คืออะไร

เป็นหนึ่งใน MariaDB Authentication Pluginsที่รองรับ Password-based Authentication.

unix_socketคืออะไร

เป็น Authentication Pluginที่ใช้ Unix Socket/OS User Contextและพบได้กับ Local Accounts เช่น root@localhostใน MariaDB Installationsหลายแบบ.

FiveMควรใช้ rootไหม

ไม่ควรใช้ rootเป็นทางลัดแก้1045 ควรใช้ Dedicated Application Account

sudo mariadb เข้าได้แต่ FiveMไม่ได้ทำไม

Root Accountอาจใช้ unix_socket Authentication ซึ่งไม่เหมือน Remote/Application Password Authentication.

Errorหลังเปลี่ยน Passwordทำอย่างไร

Update Connection String/Secretของ FiveMให้ตรง Accountใหม่

Errorหลังย้าย VPSทำอย่างไร

ตรวจทั้ง User@Host, Passwordและ Source Hostใหม่

Errorหลัง MariaDB Migrationทำอย่างไร

ตรวจ Account, Host, Authentication Pluginและ Grantsบน Serverใหม่

Errorหลัง Restore Databaseทำอย่างไร

ตรวจ MariaDB Application Accountแยกจาก Gameplay Tables เพราะ Data Restoreไม่ได้รับประกันว่า Account Configurationจะตรง Environmentเดิม

Errorหลังเปลี่ยน Database Nameทำอย่างไร

ตรวจ Grantsบน Databaseใหม่ เพราะ MariaDBระบุ Database Privilegeไม่พอเป็น Possible Causeของ Access Denied.

Resourceเดียวขึ้น1045ทำไม

Resourceนั้นอาจใช้ Connection Stringหรือ Database Accountแยกจาก Core

ทุก Resourceขึ้น1045ทำไม

Core Database Wrapper/Credentialอาจผิด

CLIผ่านแต่ FiveMไม่ผ่านทำอย่างไร

ตรวจ FiveM Connection String, Environment Variablesและ Wrapper Configuration

CLIจาก FiveM Hostก็1045ทำอย่างไร

ตรวจ MariaDB Account, Password, Host, Authentication Pluginและ Grants

Testจาก Laptopแทนได้ไหม

ไม่ดีที่สุด เพราะ MariaDB Account Matchingขึ้นกับ Hostด้วย

ต้อง Restart MariaDBไหม

ไม่ใช่ First Fixของ1045

Restart FiveMช่วยไหม

ช่วย Reload Configได้ถ้าค่า Connection Stringถูกแก้แล้วและ Wrapperต้อง Restart แต่ไม่ได้แก้ Credentialที่ยังผิด

Clear FiveM Cacheช่วยไหม

ไม่

เพิ่ม max_connectionsช่วยไหม

ไม่

เพิ่ม max_connect_errorsช่วยไหม

ไม่

เพิ่ม wait_timeoutช่วยไหม

ไม่

เพิ่ม net_read_timeoutช่วยไหม

ไม่

เพิ่ม max_allowed_packetช่วยไหม

ไม่

Error1045หมายความว่าโดน Hackไหม

ไม่ Errorเดียวไม่พิสูจน์การโจมตี อาจเป็นเพียง Passwordเก่าหรือ Configผิด

1045เกิดจำนวนมากผิดปกติควรทำอะไร

ตรวจ Source Hostและ Access Denied Monitoring เพราะ MariaDBมี access_denied_errors สำหรับเหตุการณ์ที่ Login/Privileges/SSL Requirementsไม่ผ่าน.

Unknown IPพยายาม Loginควรทำอย่างไร

ตรวจ Firewall/Network Exposureและ Accounts ไม่ควร Grant Accessให้ Unknown Host

ใช้ % แก้ได้ไหม

ไม่ควรเปิด Host Scopeกว้างขึ้นเพียงเพื่อแก้1045 ถ้า FiveMมี Source Hostที่ระบุได้

ใช้ GRANT ALL ON *.* ดีไหม

ไม่ควรเป็น Default Solution ควรให้เฉพาะ Database/Privilegesที่ Applicationต้องใช้

ใช้ skip-grant-tables ได้ไหม

ไม่ควรใช้กับ Application Authentication Problemปกติ เพราะเป็นโหมด Bypass Privilege Systemสำหรับ Recoveryเฉพาะกรณี

ต้อง Reinstall MariaDBไหม

ไม่

ต้องลบ Userไหม

ไม่ควรเป็น First Fix ให้ตรวจ SHOW CREATE USER และ SHOW GRANTS ก่อน.

ต้องลบ Databaseไหม

ไม่

ต้อง Backupไหม

ก่อนเปลี่ยน Gameplay Data/Schema/Migrationควร Backupตามปกติ ส่วนการแก้ Password/User Accountควรจด Account Definitionและ Grantsไว้ก่อนเปลี่ยน

สรุป FiveM MySQL Access Denied for User Error 1045

FiveM MySQL/MariaDB Error 1045 Access denied for user เกิดเมื่อ Account ที่ FiveM ใช้ไม่ผ่าน Authentication หรือไม่มี Access ที่จำเป็น โดย MariaDB กำหนด Error นี้เป็น ER_ACCESS_DENIED_ERROR, SQLSTATE 28000 และระบุ Username/Password Combination ที่ไม่ถูกต้องหรือ Database Privileges ไม่เพียงพอเป็น Possible Causes.

จำ Flow นี้ไว้:

1045
↓
อ่านข้อความ user@host
↓
ดู using password YES/NO
↓
ตรวจ Connection String
↓
ตรวจ SHOW CREATE USER
↓
ตรวจ Authentication Plugin
↓
ตรวจ SHOW GRANTS
↓
ทดสอบจาก FiveM Hostจริง
↓
แก้ Password / Account / Plugin / Privileges

สิ่งที่ comsiam แนะนำคืออย่าเห็น 1045 แล้ว Reset Password หรือสร้าง 'fivem'@'%' ทันที เพราะ MariaDB Account ผูกทั้ง Username, Host และ Authentication Method การแก้ Password ให้ Account ผิด Hostจะไม่ช่วยอะไร และการเปิด Hostกว้างเกินจำเป็นเพียงเพิ่มความเสี่ยง ควรใช้ SHOW CREATE USER กับ SHOW GRANTS เพื่อดู Accountที่มีอยู่จริงก่อนเปลี่ยน Configuration.

อีกหลักที่ comsiam แนะนำคือถ้า Command-line Testจาก FiveM Hostด้วย Accountเดียวกันผ่าน แต่ FiveMยังขึ้น1045 ให้หยุดแก้ MariaDBแล้วกลับไปตรวจ Connection String, Environment Variableและ Database Wrapper เพราะ MariaDB Accountทำงานได้แล้ว แต่ Applicationอาจยังใช้ Username, Password, Hostหรือ Databaseคนละค่ากับที่ทดสอบ วิธีนี้จะลดการแก้ User/Privilegesเกินความจำเป็นและรักษาความปลอดภัยของ Production Databaseไว้ได้

Comments

Popular posts from this blog

FiveM ยังน่าเล่นไหม? Enhanced เปลี่ยน FiveM แค่ไหน

FiveM คืออะไร เล่นอย่างไร สำหรับมือใหม่ เริ่มต้นตั้งแต่ศูนย์

วิธีตั้ง Admin Permission ด้วย add_ace และ add_principal FiveM แบบละเอียด