Is it secure to not refuse permissions in a non-referenced assembly?

From: Keith Patrick (richard_keith_patrick_at_hotmail.com)
Date: 09/11/03


Date: Thu, 11 Sep 2003 14:27:29 -0500


If I want to refuse all unnecessary permissions, should I add references to
those permissions that aren't even referenced in my project? I know the
idea is to be able to permview an assembly and know that it can't, for
instance, query a database, but if I do not reference the assembly that
would allow that, I would think that I can prove that my app doesn't query a
DB just by looking at its referenced assemblies. On the other hand, I
realize that I could conceivably load the assembly dynamically and invoke a
method call that way. But if that is true, then I would have to add
references to several assemblies I don't use just to refuse all 19 built-in
permissions.



Relevant Pages

  • Re: Is it secure to not refuse permissions in a non-referenced assembly?
    ... You could do a PermitOnly on the permissions your assembly uses. ... > If I want to refuse all unnecessary permissions, should I add references ... I would think that I can prove that my app doesn't query ... > DB just by looking at its referenced assemblies. ...
    (microsoft.public.dotnet.security)
  • Re: Certain users cant connect to OWA
    ... I've seen lots of references to the 401.1 indicating permissions, ... very old e-mail distribution group that had migrated from Exch 5.5. ... I couldn' see anything odd. ...
    (microsoft.public.exchange.admin)
  • Re: Read only when loging in
    ... It has been awhile since I did this. ... permissions and can not write out new records. ... not have any references or can I find any references on this. ...
    (microsoft.public.access.security)
  • Re: Read only when loging in
    ... How did you send the file - via CD/email? ... Microsoft Access MVP ... permissions and can not write out new records. ... not have any references or can I find any references on this. ...
    (microsoft.public.access.security)
  • Meeting Request gets NDR on Deleted User
    ... permissions to quite a few of our users and purged the ... mailbox and, even after removing the zombie references in ... purge the references without checking and cleaning the ... properties of every folder of every user they had access ...
    (microsoft.public.exchange2000.admin)