use of application roles

From: Sandy (sandra.carr1_at_jsc.nasa.gov)
Date: 06/26/03

  • Next message: JT: "Re: Service Account"
    Date: Thu, 26 Jun 2003 13:15:40 -0700
    
    

    Question 1: If I use SQL Server 2000's 'application role'
    to let my users enter data via a custom application, am I
    creating a security hole because of the hardcoded username
    & password?

    Background: The application allows users to logon via
    passthrough Windows authentication. The users enter data
    into the application and have no reason to directly access
    the database. The application puts the data into the
    correct tables and keeps an audit trail.

    Question 2: Do the users need any rights to the database
    if the 'application role' is used?


  • Next message: JT: "Re: Service Account"

    Relevant Pages

    • Re: typed datasets vs. business objects
      ... When I use a business object to populate a gridview, for example, I ... don't have to loop through anything. ... I have done lots and lots and lots of reading on them vs custom ... DAL objects that the in-house written database engine used. ...
      (microsoft.public.dotnet.general)
    • RE: getting Membership userid to use and store in a custom databas
      ... I would like to use the key in a many to one database the (one being your ... custom home page. ... what you'd like to do is something like the Profile ... getting Membership userid to use and store in a custom ...
      (microsoft.public.dotnet.framework.aspnet.webcontrols)
    • Re: Dear Mr. Wainwright, et al... please help re: database corruption
      ... My Entourage 'custom views' seems to be damaged. ... I get a message that my database is damaged with the following detailed ... have a lot of mail accounts, folder, rules etc that needed setting up again. ...
      (microsoft.public.mac.office.entourage)
    • BCM Sharing, Add-Ins and Synchronization
      ... additional information on a new region within a BCM Account. ... Let me say first that simply using custom fields is not feasible due to ... didn't seem to work when using a shared database. ... Is there some built-in feature of the BCM synch mechanism that can ...
      (microsoft.public.outlook.program_forms)
    • Question...
      ... generate custom .asp code to access the database and to ... interrogate the data with custom SQL. ... uploading files - hence my move to FP2003. ...
      (microsoft.public.frontpage.client)