Click here to Skip to main content
15,900,110 members
Home / Discussions / Database
   

Database

 
AnswerRe: sql server 2005 User defined datatype and PrimaryKey Pin
andyharman16-May-07 8:03
professionalandyharman16-May-07 8:03 
QuestionDatabase Security Pin
Tristan Rhodes9-May-07 4:49
Tristan Rhodes9-May-07 4:49 
AnswerRe: Database Security Pin
kubben9-May-07 14:35
kubben9-May-07 14:35 
GeneralRe: Database Security Pin
Tristan Rhodes10-May-07 1:49
Tristan Rhodes10-May-07 1:49 
GeneralRe: Database Security Pin
kubben10-May-07 1:56
kubben10-May-07 1:56 
GeneralRe: Database Security Pin
Tristan Rhodes10-May-07 2:44
Tristan Rhodes10-May-07 2:44 
GeneralRe: Database Security Pin
kubben10-May-07 3:23
kubben10-May-07 3:23 
GeneralRe: Database Security Pin
Tristan Rhodes10-May-07 3:47
Tristan Rhodes10-May-07 3:47 
Hi Ben,

Using an ACL, authenticated and authorised users could both view / edit / delete, however, normal users can only edit / delete their own unlocked records, not edit / delete someone elses records, OR their own records if they are locked, and an admin user could do anything.

Alternatively, a normal user could not Lock / Unlock any records, wheras an admin user could.

Therefore, merely being authorised on the top level via windows / db security would not be enough to stop a logged in user from deleting any records, and further permission checking would be required.

This isn't about the ability to access the database, but the ability to restrict certain sets of functionality on the database whilst logged in. I am already using a role based system, but was looking to make it slightly deeper than just testing the user roles when recieving a HTTP request.

The problem here is that, if a table contains certain fields that only an admin user should be able to change, and i am running a full record CRUD system (I think thats table direct), it would be an easy matter to enable a normal user to perform admin tasks by mistake, and not have a way to test this via permissions.

-------------------------------

Carrier Bags - 21st Century Tumbleweed.

GeneralRe: Database Security Pin
kubben10-May-07 3:51
kubben10-May-07 3:51 
GeneralRe: Database Security Pin
Tristan Rhodes10-May-07 4:46
Tristan Rhodes10-May-07 4:46 
QuestionUpdate a table from a data set Pin
G_Sankar9-May-07 3:02
G_Sankar9-May-07 3:02 
QuestionCan anyone reccomend a data access layer tool Pin
Andrew Torrance9-May-07 2:39
Andrew Torrance9-May-07 2:39 
AnswerRe: Can anyone reccomend a data access layer tool Pin
LongRange.Shooter16-May-07 7:48
LongRange.Shooter16-May-07 7:48 
QuestionCalling stored procedures within MFC code Pin
Ahmed Charfeddine9-May-07 2:29
Ahmed Charfeddine9-May-07 2:29 
QuestionDatabase Connection problem in sql server 2005 Pin
hbk_leo9-May-07 2:06
hbk_leo9-May-07 2:06 
AnswerRe: Database Connection problem in sql server 2005 Pin
Ahmed Charfeddine9-May-07 2:35
Ahmed Charfeddine9-May-07 2:35 
GeneralConnect Directly to SQL Server File Pin
Brady Kelly9-May-07 0:55
Brady Kelly9-May-07 0:55 
AnswerRe: Connect Directly to SQL Server File Pin
andyharman9-May-07 1:57
professionalandyharman9-May-07 1:57 
QuestionAccessing database file (.sdf) after changing extension (say .abc) causes error in connection string. Pin
ManishJape9-May-07 0:51
ManishJape9-May-07 0:51 
Questionget the table name in a .mdb file Pin
hero19958-May-07 23:41
hero19958-May-07 23:41 
AnswerRe: get the table name in a .mdb file Pin
hero19959-May-07 21:37
hero19959-May-07 21:37 
Questionneed query(urgent) Pin
Revathi Raj8-May-07 23:30
Revathi Raj8-May-07 23:30 
AnswerRe: need query(urgent) Pin
Colin Angus Mackay8-May-07 23:36
Colin Angus Mackay8-May-07 23:36 
QuestionHow to diplay reports in reportview control?Pls help its URGENT!! Pin
sha_shivani8-May-07 13:34
sha_shivani8-May-07 13:34 
GeneralSearch Routine Pin
Brady Kelly8-May-07 4:55
Brady Kelly8-May-07 4:55 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.