i recently noticed that the programmer has been adding the users of our applications to the actual users under our database. When i inquired as to why, he said it was the only way they could access the data. I also noticed that the users all have been set to owners. I spoke with another friend and he said as far as he knew there wasn't any real reason why the application users would have to be set up in the actual database but just in a table/field, but that they really don't need to be owners. This app is designed to have thousands and thousands of users, and it seem like this is going to be difficult to manage.
Any thoughts?There seems to many ways you can implement security, Windows Authentication, SQL Server mode, Application Roles, individual user accounts, single application accounts.
To shorten the response I will just say how we implemented security. Like you we have about 2000 users that access the database via one of many applications. We elected to create a single user account for each application (example: Payroll - INetPayroll). Each enduser would enter there logon information into a logon screen (.ASP) and be validated against a security table that listed every user and there password. Once validated the application would then connect to the database using it's own SQL Server account (INetPayroll). This way we limited the number of user accounts that had to be maintained in the database, security would only be granted to a few user accounts, we implemented GROUPs and added users (INetPayroll) to the GROUPs, there by only needing to grant permission to the GROUP only. We couldn't use NT authentication because we deal with NOVELL users and all applications are via Intranet and connections are made with the IIS user account.
By making every user the owner you have opened up a can of worms. This is the lazy mans way of doing it. If a user has MS Access on their desktop or MS Query, they could connect to the database directly and access to database. As owners they can now modify any data directly, drop create objects, not good.
In our implementation user don't really have a SQL Server account so they can not access the database directly.
You may want to look at Application Roles.|||and as a follow on to achorozy, I NEVER allow programmers direct access to production dbs & tables. If they can't get to what they want via an application & stored procedures they are out of luck. That always has been a tuff argument to make to managment and there will always be an exception but this is one area I won't back down on. Security can never be taken to seriously.|||I don't want to side track here, but Paul brings up a good point. In our environment all data access, manipulation is done through stored procedures and not direct SQL statements. Were I work only the DBAs create the stored procedures and database objects, the developers write the VB/ASP code, design the screens, etc.
I wish I could be a little survey here and find out how many people that subscribe to this forum are in fact DBAs at there site or have a DBA at there site. Are any of you out there developers/programmers thrown into the DBA role? Do you want to take on the responsiblities of a DBA or are you just doing enough to get by, to get the system up and running?
Just some thought I have.sql
Showing posts with label applications. Show all posts
Showing posts with label applications. Show all posts
Sunday, March 25, 2012
creating users in sql 2000
Sunday, March 11, 2012
creating SQL at setup
I must install web applications on many servers
how can I create a MS SQL database at setup ?
how can I create a MS SQL database at setup ?
thank youOne option is to script the db and use OSQL to execute the script.|||what is OSQL ?|||By using osql utility, you can run sql commands from command prompt.
You can run batch scripts that are saved in a text file, and also save the returned results in a text file.|||yes ... that's so unpracticle comparing to access :-))
thank you
Creating RS Folders
We are setting up a Reporting Server and are categorizing our reports by
departments and applications within the departments. I have a long list of
these categorizations which are in the follwing format:
Dept1 App1 Rept1
Dept1 App2 Rept1
Dept2 App1 Rept1
Dept2 App3 Rept1
Dept3 App2 Rept1
...
My two questions are:
1) What is the fastest way for me to create all the folders to reflect the
categorizations as listed above (can this be done faster than just doing it
manually)
2) Once the folder structures have been set up. Can I somehow save this or
script it out for future server builds?Look into using rs.exe to create the folders. You can also use any .Net
language to make SOAP calls to create the folder structure, creating an .exe
that will create them on any RS machine you want.
--
-Daniel
This posting is provided "AS IS" with no warranties, and confers no rights.
"DBA72" <DBA72@.discussions.microsoft.com> wrote in message
news:32995ABD-3B01-4F4B-8854-6B0108ADC401@.microsoft.com...
> We are setting up a Reporting Server and are categorizing our reports by
> departments and applications within the departments. I have a long list of
> these categorizations which are in the follwing format:
> Dept1 App1 Rept1
> Dept1 App2 Rept1
> Dept2 App1 Rept1
> Dept2 App3 Rept1
> Dept3 App2 Rept1
> ...
> My two questions are:
> 1) What is the fastest way for me to create all the folders to reflect the
> categorizations as listed above (can this be done faster than just doing
> it
> manually)
> 2) Once the folder structures have been set up. Can I somehow save this or
> script it out for future server builds?|||Daniel,
In using the SOAP calls, with forms authentication set up, it appears we'll
need to make sure the forms auth cookie gets through. (I can't get rs.exe
to work, and I presume it's because that cookie isn't there.)
From what I've heard, this means the .NET app we create needs to be a web
service or web app to have visibility into the web security context. Is
that correct?
Thanks,
'(' Jeff A. Stucker
\
Business Intelligence
www.criadvantage.com
---
"Daniel Reib [MSFT]" <danreib@.online.microsoft.com> wrote in message
news:ONReSH18EHA.3124@.TK2MSFTNGP11.phx.gbl...
> Look into using rs.exe to create the folders. You can also use any .Net
> language to make SOAP calls to create the folder structure, creating an
> .exe that will create them on any RS machine you want.
> --
> -Daniel
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
> "DBA72" <DBA72@.discussions.microsoft.com> wrote in message
> news:32995ABD-3B01-4F4B-8854-6B0108ADC401@.microsoft.com...
>> We are setting up a Reporting Server and are categorizing our reports by
>> departments and applications within the departments. I have a long list
>> of
>> these categorizations which are in the follwing format:
>> Dept1 App1 Rept1
>> Dept1 App2 Rept1
>> Dept2 App1 Rept1
>> Dept2 App3 Rept1
>> Dept3 App2 Rept1
>> ...
>> My two questions are:
>> 1) What is the fastest way for me to create all the folders to reflect
>> the
>> categorizations as listed above (can this be done faster than just doing
>> it
>> manually)
>> 2) Once the folder structures have been set up. Can I somehow save this
>> or
>> script it out for future server builds?
>|||Daniel (or any other MSFT person or person with experience) ... Do we need
to create a web service or web app to *script* reporting services *with
forms auth running*?
I appreciate any replies, thanks,
'(' Jeff A. Stucker
\
Business Intelligence
www.criadvantage.com
---
"Jeff A. Stucker" <jeff@.mobilize.net> wrote in message
news:uJwZkKR9EHA.1300@.TK2MSFTNGP14.phx.gbl...
> Daniel,
> In using the SOAP calls, with forms authentication set up, it appears
> we'll need to make sure the forms auth cookie gets through. (I can't get
> rs.exe to work, and I presume it's because that cookie isn't there.)
> From what I've heard, this means the .NET app we create needs to be a web
> service or web app to have visibility into the web security context. Is
> that correct?
> Thanks,
> '(' Jeff A. Stucker
> \
> Business Intelligence
> www.criadvantage.com
> ---
> "Daniel Reib [MSFT]" <danreib@.online.microsoft.com> wrote in message
> news:ONReSH18EHA.3124@.TK2MSFTNGP11.phx.gbl...
>> Look into using rs.exe to create the folders. You can also use any .Net
>> language to make SOAP calls to create the folder structure, creating an
>> .exe that will create them on any RS machine you want.
>> --
>> -Daniel
>> This posting is provided "AS IS" with no warranties, and confers no
>> rights.
>>
>> "DBA72" <DBA72@.discussions.microsoft.com> wrote in message
>> news:32995ABD-3B01-4F4B-8854-6B0108ADC401@.microsoft.com...
>> We are setting up a Reporting Server and are categorizing our reports by
>> departments and applications within the departments. I have a long list
>> of
>> these categorizations which are in the follwing format:
>> Dept1 App1 Rept1
>> Dept1 App2 Rept1
>> Dept2 App1 Rept1
>> Dept2 App3 Rept1
>> Dept3 App2 Rept1
>> ...
>> My two questions are:
>> 1) What is the fastest way for me to create all the folders to reflect
>> the
>> categorizations as listed above (can this be done faster than just doing
>> it
>> manually)
>> 2) Once the folder structures have been set up. Can I somehow save this
>> or
>> script it out for future server builds?
>>
>
departments and applications within the departments. I have a long list of
these categorizations which are in the follwing format:
Dept1 App1 Rept1
Dept1 App2 Rept1
Dept2 App1 Rept1
Dept2 App3 Rept1
Dept3 App2 Rept1
...
My two questions are:
1) What is the fastest way for me to create all the folders to reflect the
categorizations as listed above (can this be done faster than just doing it
manually)
2) Once the folder structures have been set up. Can I somehow save this or
script it out for future server builds?Look into using rs.exe to create the folders. You can also use any .Net
language to make SOAP calls to create the folder structure, creating an .exe
that will create them on any RS machine you want.
--
-Daniel
This posting is provided "AS IS" with no warranties, and confers no rights.
"DBA72" <DBA72@.discussions.microsoft.com> wrote in message
news:32995ABD-3B01-4F4B-8854-6B0108ADC401@.microsoft.com...
> We are setting up a Reporting Server and are categorizing our reports by
> departments and applications within the departments. I have a long list of
> these categorizations which are in the follwing format:
> Dept1 App1 Rept1
> Dept1 App2 Rept1
> Dept2 App1 Rept1
> Dept2 App3 Rept1
> Dept3 App2 Rept1
> ...
> My two questions are:
> 1) What is the fastest way for me to create all the folders to reflect the
> categorizations as listed above (can this be done faster than just doing
> it
> manually)
> 2) Once the folder structures have been set up. Can I somehow save this or
> script it out for future server builds?|||Daniel,
In using the SOAP calls, with forms authentication set up, it appears we'll
need to make sure the forms auth cookie gets through. (I can't get rs.exe
to work, and I presume it's because that cookie isn't there.)
From what I've heard, this means the .NET app we create needs to be a web
service or web app to have visibility into the web security context. Is
that correct?
Thanks,
'(' Jeff A. Stucker
\
Business Intelligence
www.criadvantage.com
---
"Daniel Reib [MSFT]" <danreib@.online.microsoft.com> wrote in message
news:ONReSH18EHA.3124@.TK2MSFTNGP11.phx.gbl...
> Look into using rs.exe to create the folders. You can also use any .Net
> language to make SOAP calls to create the folder structure, creating an
> .exe that will create them on any RS machine you want.
> --
> -Daniel
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
> "DBA72" <DBA72@.discussions.microsoft.com> wrote in message
> news:32995ABD-3B01-4F4B-8854-6B0108ADC401@.microsoft.com...
>> We are setting up a Reporting Server and are categorizing our reports by
>> departments and applications within the departments. I have a long list
>> of
>> these categorizations which are in the follwing format:
>> Dept1 App1 Rept1
>> Dept1 App2 Rept1
>> Dept2 App1 Rept1
>> Dept2 App3 Rept1
>> Dept3 App2 Rept1
>> ...
>> My two questions are:
>> 1) What is the fastest way for me to create all the folders to reflect
>> the
>> categorizations as listed above (can this be done faster than just doing
>> it
>> manually)
>> 2) Once the folder structures have been set up. Can I somehow save this
>> or
>> script it out for future server builds?
>|||Daniel (or any other MSFT person or person with experience) ... Do we need
to create a web service or web app to *script* reporting services *with
forms auth running*?
I appreciate any replies, thanks,
'(' Jeff A. Stucker
\
Business Intelligence
www.criadvantage.com
---
"Jeff A. Stucker" <jeff@.mobilize.net> wrote in message
news:uJwZkKR9EHA.1300@.TK2MSFTNGP14.phx.gbl...
> Daniel,
> In using the SOAP calls, with forms authentication set up, it appears
> we'll need to make sure the forms auth cookie gets through. (I can't get
> rs.exe to work, and I presume it's because that cookie isn't there.)
> From what I've heard, this means the .NET app we create needs to be a web
> service or web app to have visibility into the web security context. Is
> that correct?
> Thanks,
> '(' Jeff A. Stucker
> \
> Business Intelligence
> www.criadvantage.com
> ---
> "Daniel Reib [MSFT]" <danreib@.online.microsoft.com> wrote in message
> news:ONReSH18EHA.3124@.TK2MSFTNGP11.phx.gbl...
>> Look into using rs.exe to create the folders. You can also use any .Net
>> language to make SOAP calls to create the folder structure, creating an
>> .exe that will create them on any RS machine you want.
>> --
>> -Daniel
>> This posting is provided "AS IS" with no warranties, and confers no
>> rights.
>>
>> "DBA72" <DBA72@.discussions.microsoft.com> wrote in message
>> news:32995ABD-3B01-4F4B-8854-6B0108ADC401@.microsoft.com...
>> We are setting up a Reporting Server and are categorizing our reports by
>> departments and applications within the departments. I have a long list
>> of
>> these categorizations which are in the follwing format:
>> Dept1 App1 Rept1
>> Dept1 App2 Rept1
>> Dept2 App1 Rept1
>> Dept2 App3 Rept1
>> Dept3 App2 Rept1
>> ...
>> My two questions are:
>> 1) What is the fastest way for me to create all the folders to reflect
>> the
>> categorizations as listed above (can this be done faster than just doing
>> it
>> manually)
>> 2) Once the folder structures have been set up. Can I somehow save this
>> or
>> script it out for future server builds?
>>
>
Labels:
applications,
categorizing,
creating,
database,
departments,
folders,
microsoft,
mysql,
oracle,
reporting,
reports,
server,
setting,
sql
Wednesday, March 7, 2012
Creating object type
How to create object type in sql server,
i.e in Oracle we can directly create an object TYPE and we can use it in other applications.
What's the equivalent of this object Type in SQL Serverdo you mean a user defined type?|||Yes, a user defined type|||have a look at udts in BOL:
for CLR based types (2005 only): http://msdn2.microsoft.com/en-us/library/ms131106.aspx
for SQL based types:
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/tsqlref/ts_sp_addp_584l.asp (2000 syntax, deprecated in 2005 - there you should use CREATE TYPE instead)|||I was going to bring up CLR triggers here but I am not sure I want all of that application code running under my sql service. The book I am writing makes a fair case for some things .Net does faster than sql like string manipulation, running totals and such but I am not sure I am sold yet.
i.e in Oracle we can directly create an object TYPE and we can use it in other applications.
What's the equivalent of this object Type in SQL Serverdo you mean a user defined type?|||Yes, a user defined type|||have a look at udts in BOL:
for CLR based types (2005 only): http://msdn2.microsoft.com/en-us/library/ms131106.aspx
for SQL based types:
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/tsqlref/ts_sp_addp_584l.asp (2000 syntax, deprecated in 2005 - there you should use CREATE TYPE instead)|||I was going to bring up CLR triggers here but I am not sure I want all of that application code running under my sql service. The book I am writing makes a fair case for some things .Net does faster than sql like string manipulation, running totals and such but I am not sure I am sold yet.
Subscribe to:
Posts (Atom)