Can someone please point to me how the architecture of a web site where database access is required should be used…
I have a site that connects to a SQL express database and I have a provider setup in the web config file to access the database. If a user logs into the site they will use this username and password to access data and determine if it is a valid user. (This password is at this time unencrypted)
If someone should get hold of this password they can have access to the database and do what they want to. Is this correct? Or should I do something else? Also what roles should this common user have?
If a user logs into the site they will use this username and password to access data
Are you talking about the user that is registered into the database. Means are they just a single record from Users table of the Database or they are the actual user which is used to connect to the database.
Generally, uid and password can be protected using SSL connection.
Yes if you send password unencrypted, it might be exposed to others. But if they are not sensitive enough, it is unnecessary to do Encryption using SSL.
For our general websites , We take uid and password and check with db using the connection string(which has UID and password) stored in the server.
I dont think from ASP.NET, anyone can get the UID and password as it is secure and cant be called. If you are unsure that someone else who have access to the server can see it through file system, you can also make use of encryption of web.config.
Now regarding the role, you can either make it db_owner or sys_admin based on the requirement.
In my table there is a coloum CreatedDate(DateTime) which stores datetime in UCT Time.
Now I want to show this time to user's local time.(i.e. User From US can see US time, User from india can see Indian local time.) how can i convert? should i have go through Cultureinfo? or may it creates daylight saving problem?
We have developed an (ASP.NET) Web Application in VS 2008 & developed a setup project for the same and successfully installed in our local environment (Windows XP/ Windows 2003 server).
This web setup project contains the below:
1. Web Application (Primary output/ Content)
2. Primary output of BLL & DAL
3. Few custom actions
4. Few UI Forms to get the Database details/ etc from user
5. One Windows service
This setup fails immediatley in the client environment. The client also using the Windows XP SP2/ 32 bit version. But the windows root folder is "C:\WINNT"; bcos the system has been upgraded from Windows 2000 to XP it seems.
After that we have removed the custom actions and Windows service from the setup project (to narrow down the issue) & tried to install, it also failed.
We dont have any clue on this. Can you please help...
i want separate two columns of crystal report by colon( .and i want 3 records of two column in half vertical portion of the page and next 3 records display on remaining part of same page with colon.
and i mean i want something like this please help me
Sno rollno student name Sno rollno student name
1. 001:A 4. 004
2. 002:B 5. 005:E
3. 003:C 6. 006:F
i m using radiobuttonlist with images like this
<asp:RadioButtonList ID="rbtnthumb1" runat="server">
<asp:ListItem Value ="News_icon.jpg"> <img src="images/News_icon.jpg" alt="News" align="absmiddle"> News</asp:ListItem>
<asp:ListItem Value ="imageicon.bmp"><img src="images/imageicon.bmp" alt="Image" align="absmiddle">Image</asp:ListItem>
<asp:ListItem Value ="Video97.gif" ><img src="images/Video97.gif" alt="Video" align="absmiddle">Video</asp:ListItem>
In design view it show radiobuttonlist with images but when i use insert query.it stored this value in mytable
<img src="images/News_icon.jpg" alt="News" align="absmiddle"> News
but i only want to store News_icon.jpg(image file name)and i m using this way for adding value
please let me know how to stroe only imagefile name in database table