Hello All,
I am a newbie here coming from a Crystal development background and
intermediate skills with SQL. I seem to have various issues creating
all sorts of RS reports. I'm trying to start with "more modest"
reports to ease myself into the groove of using RS, but some things
that seem simple stump me.
I have a simple query that brings back 24 results. I used the wizard
to create a simple layout using 1 group (I expect 12 "subsections" by
using this group) with the details displayed under each group.
For whatever odd reason, even tho' running the query finds the 24
results, the Preview shows 1 result. I even removed the group and ran
all the details (tried refreshing) and only 1 result again.
Any ideas?
Thank you in advance
-ColleenOn Apr 27, 10:58 am, Colleen <colleenleon...@.gmail.com> wrote:
> Hello All,
> I am a newbie here coming from a Crystal development background and
> intermediate skills with SQL. I seem to have various issues creating
> all sorts of RS reports. I'm trying to start with "more modest"
> reports to ease myself into the groove of using RS, but some things
> that seem simple stump me.
> I have a simple query that brings back 24 results. I used the wizard
> to create a simple layout using 1 group (I expect 12 "subsections" by
> using this group) with the details displayed under each group.
> For whatever odd reason, even tho' running the query finds the 24
> results, the Preview shows 1 result. I even removed the group and ran
> all the details (tried refreshing) and only 1 result again.
> Any ideas?
> Thank you in advance
> -Colleen
It sounds kind-of like your group had the Property 'Page break at end'
set. Also, make sure you don't have a filter set. Hope this helps.
Regards,
Enrique Martinez
Sr. Software Consultant|||I think grouping has done with 1 row than 24
what you do is create a new project->report and place the same query and see
whether you get the same results. ofcourse place a table control and just
drag and drop a couple of fields and see whether you get 24 rows.?
Amarnath
"Colleen" wrote:
> Hello All,
> I am a newbie here coming from a Crystal development background and
> intermediate skills with SQL. I seem to have various issues creating
> all sorts of RS reports. I'm trying to start with "more modest"
> reports to ease myself into the groove of using RS, but some things
> that seem simple stump me.
> I have a simple query that brings back 24 results. I used the wizard
> to create a simple layout using 1 group (I expect 12 "subsections" by
> using this group) with the details displayed under each group.
> For whatever odd reason, even tho' running the query finds the 24
> results, the Preview shows 1 result. I even removed the group and ran
> all the details (tried refreshing) and only 1 result again.
> Any ideas?
> Thank you in advance
> -Colleen
>|||My guess is that you dragged and dropped your fields onto an empty canvas.
If you do this you will see only one record because you did not put either a
table or list control on the canvas first.
Bruce Loehle-Conger
MVP SQL Server Reporting Services
"Colleen" <colleenleonard@.gmail.com> wrote in message
news:1177689534.303004.210340@.r30g2000prh.googlegroups.com...
> Hello All,
> I am a newbie here coming from a Crystal development background and
> intermediate skills with SQL. I seem to have various issues creating
> all sorts of RS reports. I'm trying to start with "more modest"
> reports to ease myself into the groove of using RS, but some things
> that seem simple stump me.
> I have a simple query that brings back 24 results. I used the wizard
> to create a simple layout using 1 group (I expect 12 "subsections" by
> using this group) with the details displayed under each group.
> For whatever odd reason, even tho' running the query finds the 24
> results, the Preview shows 1 result. I even removed the group and ran
> all the details (tried refreshing) and only 1 result again.
> Any ideas?
> Thank you in advance
> -Colleen
>|||Other things to check might be that you are not pulling the "first" value in your expression. In your Datasets drill down it may only offer the choice to pull your first value.
From http://www.developmentnow.com/g/115_2007_4_0_0_964026/Dataset-Run-finds-24-results-Preview-displays-1-results.ht
Posted via DevelopmentNow.com Group
http://www.developmentnow.com|||On Apr 29, 8:45 pm, "Bruce L-C [MVP]" <bruce_lcNOS...@.hotmail.com>
wrote:
> My guess is that you dragged and dropped your fields onto an empty canvas.
> If you do this you will see only one record because you did not put either a
> table or list control on the canvas first.
> --
> Bruce Loehle-Conger
> MVP SQL Server Reporting Services
> "Colleen" <colleenleon...@.gmail.com> wrote in message
> news:1177689534.303004.210340@.r30g2000prh.googlegroups.com...
>
> > Hello All,
> > I am a newbie here coming from a Crystal development background and
> > intermediate skills with SQL. I seem to have various issues creating
> > all sorts of RS reports. I'm trying to start with "more modest"
> > reports to ease myself into the groove of using RS, but some things
> > that seem simple stump me.
> > I have a simple query that brings back 24 results. I used the wizard
> > to create a simple layout using 1 group (I expect 12 "subsections" by
> > using this group) with the details displayed under each group.
> > For whatever odd reason, even tho' running the query finds the 24
> > results, the Preview shows 1result. I even removed the group and ran
> > all the details (tried refreshing) and only 1resultagain.
> > Any ideas?
> > Thank you in advance
> > -Colleen- Hide quoted text -
> - Show quoted text -|||On Apr 29, 8:45 pm, "Bruce L-C [MVP]" <bruce_lcNOS...@.hotmail.com>
wrote:
> My guess is that you dragged and dropped your fields onto an empty canvas.
> If you do this you will see only one record because you did not put either a
> table or list control on the canvas first.
> --
> Bruce Loehle-Conger
> MVP SQL Server Reporting Services
> "Colleen" <colleenleon...@.gmail.com> wrote in message
> news:1177689534.303004.210340@.r30g2000prh.googlegroups.com...
>
> > Hello All,
> > I am a newbie here coming from a Crystal development background and
> > intermediate skills with SQL. I seem to have various issues creating
> > all sorts of RS reports. I'm trying to start with "more modest"
> > reports to ease myself into the groove of using RS, but some things
> > that seem simple stump me.
> > I have a simple query that brings back 24 results. I used the wizard
> > to create a simple layout using 1 group (I expect 12 "subsections" by
> > using this group) with the details displayed under each group.
> > For whatever odd reason, even tho' running the query finds the 24
> > results, the Preview shows 1result. I even removed the group and ran
> > all the details (tried refreshing) and only 1resultagain.
> > Any ideas?
> > Thank you in advance
> > -Colleen- Hide quoted text -
> - Show quoted text -
---
Not sure how to reply to ALL here... thank you ALL for your help.
I could not find evidence that I selected pulling the "first" value in
the expression
I did not populate my report on an "empty canvas" as I have been using
the Report Wizard for now until I become more acclimated.
I DID try and recreate my report from scratch and did not use the
group feature in the Report Wizard and *got the desired results*. I
didn't even set up the parameter and magically somehow the report
picked it up on its own (I've has issues with other reports that even
forcefully adding the parameters to the report still doesn't seem to
"use" them). So I added the group after I had all the details
displayed and so far it works, the output looks a little different
creating the group after you create the report vs creating the group
in the wizard, but I can't be picky at this point. 280+ report left
to convert!
Thank you all very much for your ideas... I wish I understood better
how to fix the problem vs starting over, but if that is what works
then so be it.
Thanks again
-Colleen|||One point to be aware of when testing.
When you preview the report in development it will cache the data and reuse
that unless a parameter value changes. This can cause you to see something
different in preview versus deployment. If you look at where your rdl files
are you will see a .data file. This file can be deleted to force it to hit
the server for the data. Or, if your report has a parameter then just pick a
different value.
Just a heads up.
Bruce Loehle-Conger
MVP SQL Server Reporting Services
"Colleen" <colleenleonard@.gmail.com> wrote in message
news:1178028225.392190.64460@.c35g2000hsg.googlegroups.com...
> On Apr 29, 8:45 pm, "Bruce L-C [MVP]" <bruce_lcNOS...@.hotmail.com>
> wrote:
>> My guess is that you dragged and dropped your fields onto an empty
>> canvas.
>> If you do this you will see only one record because you did not put
>> either a
>> table or list control on the canvas first.
>> --
>> Bruce Loehle-Conger
>> MVP SQL Server Reporting Services
>> "Colleen" <colleenleon...@.gmail.com> wrote in message
>> news:1177689534.303004.210340@.r30g2000prh.googlegroups.com...
>>
>> > Hello All,
>> > I am a newbie here coming from a Crystal development background and
>> > intermediate skills with SQL. I seem to have various issues creating
>> > all sorts of RS reports. I'm trying to start with "more modest"
>> > reports to ease myself into the groove of using RS, but some things
>> > that seem simple stump me.
>> > I have a simple query that brings back 24 results. I used the wizard
>> > to create a simple layout using 1 group (I expect 12 "subsections" by
>> > using this group) with the details displayed under each group.
>> > For whatever odd reason, even tho' running the query finds the 24
>> > results, the Preview shows 1result. I even removed the group and ran
>> > all the details (tried refreshing) and only 1resultagain.
>> > Any ideas?
>> > Thank you in advance
>> > -Colleen- Hide quoted text -
>> - Show quoted text -
> ---
> Not sure how to reply to ALL here... thank you ALL for your help.
> I could not find evidence that I selected pulling the "first" value in
> the expression
> I did not populate my report on an "empty canvas" as I have been using
> the Report Wizard for now until I become more acclimated.
> I DID try and recreate my report from scratch and did not use the
> group feature in the Report Wizard and *got the desired results*. I
> didn't even set up the parameter and magically somehow the report
> picked it up on its own (I've has issues with other reports that even
> forcefully adding the parameters to the report still doesn't seem to
> "use" them). So I added the group after I had all the details
> displayed and so far it works, the output looks a little different
> creating the group after you create the report vs creating the group
> in the wizard, but I can't be picky at this point. 280+ report left
> to convert!
> Thank you all very much for your ideas... I wish I understood better
> how to fix the problem vs starting over, but if that is what works
> then so be it.
> Thanks again
> -Colleen
>
Showing posts with label crystal. Show all posts
Showing posts with label crystal. Show all posts
Thursday, March 22, 2012
dataset problem
hi,
i am using dataset for passing value to crystal report.
when the stored procedure contains 2 tables then how to create the dataset1.xsd for two table.
query with join works fine in QA.
i tried by giving two tables in dataset schema but how to give two tables with selected fields as per the query.
which table i should mention in fill method.
please tell me a procedure how to do this.
i tried an alternative method also.
by creating dataset at runtime using adapter.
but without filteration as per query all data appears in the report.
thanksafter setting dataset using adapter, aand setting it to crystal use record selection formula.|||iam using crystal report.net in vb.net
can you send a sample code for this.
your help will be appreciated.|||Hi u can code something like this.
Dim srcCr As Object
Dim rptDoc As New ReportDocument
srcCr = rptDoc
srcCr.SetDataSource(dsObj) --dsobj is ur dataset
rptDoc.Load("\reports\abc.rpt")
srcCr.RecordSelectionFormula = "{command.AccID}=124"
hope it helps you
i am using dataset for passing value to crystal report.
when the stored procedure contains 2 tables then how to create the dataset1.xsd for two table.
query with join works fine in QA.
i tried by giving two tables in dataset schema but how to give two tables with selected fields as per the query.
which table i should mention in fill method.
please tell me a procedure how to do this.
i tried an alternative method also.
by creating dataset at runtime using adapter.
but without filteration as per query all data appears in the report.
thanksafter setting dataset using adapter, aand setting it to crystal use record selection formula.|||iam using crystal report.net in vb.net
can you send a sample code for this.
your help will be appreciated.|||Hi u can code something like this.
Dim srcCr As Object
Dim rptDoc As New ReportDocument
srcCr = rptDoc
srcCr.SetDataSource(dsObj) --dsobj is ur dataset
rptDoc.Load("\reports\abc.rpt")
srcCr.RecordSelectionFormula = "{command.AccID}=124"
hope it helps you
Friday, February 17, 2012
Database utilities
Are database utilities, such as Crystal Designer, SQL client tools, and DB
Artisan a security risk that should be removed from the system, or is it
more effective to use the security provided by SQL Server? I think that
removal of the database utilities is unnecessary, but I have been asked to
develop software that finds the software and optionally removes it.
One reason why removal of the utilities has negligent value is that software
such as that can easily be used from other media and/or can be installed. I
know there are ways to limit use and installation of software but as far as
I know, there would be only partial security provided by doing that.
I need to learn about SQL Server security. If I am correct about what I say
above, then if I can get suggestions for what to read or read about, then
that would help.Preventing access to database utility software does not in itself provide
data security. One can write and execute a script like the one below using
only a text editor.
Set conn = CreateObject("ADODB.Connection")
conn.Open _
"Provider=SQLOLEDB;" & _
"Data Source=MyServer;" & _
"Integrated Security=SSPI;" & _
"Initial Catalog=MyDatabase;"
conn.Execute "DELETE FROM MyTable"
Of course, the user (Windows authenticated account in this example) must
have the appropriate SQL permissions in order to successfully execute such a
script and that is why attention to database security is important.
That said, it is often desirable to discourage ad-hoc SQL access to
production databases using database tools and utilities. Consider a
non-technical user with the database object permissions needed in order to
use an application. With a separate reporting tool, the user could easily
access the database from outside the application and cause blocking or other
performance problems with a poorly formed query. This is one reason why it
is common to create a separate database for end-user reporting and provide
users with the tools needed to do their job.
Applications sometimes use an application login or role to provide data
access under a security context other than the end user. This approach
provides users with the database permissions needed to use the app yet
prevents adhoc access from outside the context of the application unless the
user's own login has been granted the access and permissions.
> I need to learn about SQL Server security. If I am correct about what I
> say above, then if I can get suggestions for what to read or read about,
> then that would help.
For starters, check out 'Managing Security' topic in the Books Online. If
you don't have the doc installed, you can find it online at
http://msdn.microsoft.com/library/d...>
ity_05bt.asp
Hope this helps.
Dan Guzman
SQL Server MVP
"Sam Hobbs" <samuel@.social.rr.com_change_social_to_socal> wrote in message
news:e2EmgVP%23FHA.1332@.tk2msftngp13.phx.gbl...
> Are database utilities, such as Crystal Designer, SQL client tools, and DB
> Artisan a security risk that should be removed from the system, or is it
> more effective to use the security provided by SQL Server? I think that
> removal of the database utilities is unnecessary, but I have been asked to
> develop software that finds the software and optionally removes it.
> One reason why removal of the utilities has negligent value is that
> software such as that can easily be used from other media and/or can be
> installed. I know there are ways to limit use and installation of software
> but as far as I know, there would be only partial security provided by
> doing that.
> I need to learn about SQL Server security. If I am correct about what I
> say above, then if I can get suggestions for what to read or read about,
> then that would help.
>|||"Dan Guzman" <guzmanda@.nospam-online.sbcglobal.net> wrote in message
news:u0%23ilqQ%23FHA.4092@.TK2MSFTNGP10.phx.gbl...
> Preventing access to database utility software does not in itself provide
> data security. One can write and execute a script like the one below
> using only a text editor.
> Set conn = CreateObject("ADODB.Connection")
> conn.Open _
> "Provider=SQLOLEDB;" & _
> "Data Source=MyServer;" & _
> "Integrated Security=SSPI;" & _
> "Initial Catalog=MyDatabase;"
> conn.Execute "DELETE FROM MyTable"
The script would not actually be executed by the text editor, but otherwise
this is an example of something that would be impractical to remove. The
actual programs would be WScript and CScript. If removal of possibly risky
tools is done to protect thd data, then WScript and CScript would have to be
removed also, which would make all scripts useless. HTML scripting
capability would also have to be removed.
> it is often desirable to discourage ad-hoc SQL access to production
> databases using database tools and utilities. Consider a non-technical
> user with the database object permissions needed in order to use an
> application. With a separate reporting tool, the user could easily access
> the database from outside the application and cause blocking or other
> performance problems with a poorly formed query. This is one reason why
> it is common to create a separate database for end-user reporting and
> provide users with the tools needed to do their job.
I think that perormance is not a typical security matter. Performance
considerations such as this make the problem much more complicated. In those
situations where elimination of possible performance problems require a
security solution different from other security solutions, I think that the
benefits would not justify the cost. I think that performance problems
should not be a primary duty of security and is especially outside the scope
of my project.
> Applications sometimes use an application login or role to provide data
> access under a security context other than the end user. This approach
> provides users with the database permissions needed to use the app yet
> prevents adhoc access from outside the context of the application unless
> the user's own login has been granted the access and permissions.
I do not know if this application's login provides a different security
context; I am not aware of that, but it is worth investigating.
If the application provides the ability to execute a macro during or
immediately following an application, is it possible that the security
context could be changed then? I realize that this might not work for this
particular application, so I am asking only if it might work.
Perhaps it is possible to write a program that changes the security context
then executes the application, but that would be impractical if it requires
a separate login. I need to learn about SQL Server's roles before deciding
to use a solution such as this.
SQL Server's roles seem to be the prefered solution and I will read the
article you specify before I ask any questions about roles.|||> The script would not actually be executed by the text editor, but
> otherwise this is an example of something that would be impractical to
> remove.
You are, of course, completely correct. I should have said "write using any
text editor and execute using standard OS componenets".
> I think that perormance is not a typical security matter. Performance
> considerations such as this make the problem much more complicated. In
> those situations where elimination of possible performance problems
> require a security solution different from other security solutions, I
> think that the benefits would not justify the cost. I think that
> performance problems should not be a primary duty of security and is
> especially outside the scope of my project.
I included issues related to authorized data access because I don't know the
scope of your security project and these considerations could affect your
security analysis and design. In the broader sense, security includes
taking reasonable precautions to ensure that data are accessible by
authorized users. Some companies also include DR under the security
umbrella.
> If the application provides the ability to execute a macro during or
> immediately following an application, is it possible that the security
> context could be changed then? I realize that this might not work for this
> particular application, so I am asking only if it might work.
> Perhaps it is possible to write a program that changes the security
> context then executes the application, but that would be impractical if it
> requires a separate login. I need to learn about SQL Server's roles before
> deciding to use a solution such as this.
>
I'm not sure I understand what you mean by 'macro'. If you are referring to
SQL script and the script is run by the app immediately after each database
connection, such an approach might allow you to enable an application role.
AFAIK, other 'macro' techniques would require separate accounts.
Hope this helps.
Dan Guzman
SQL Server MVP
"Sam Hobbs" <samuel@.social.rr.com_change_social_to_socal> wrote in message
news:O8AvMGo%23FHA.272@.TK2MSFTNGP09.phx.gbl...
> "Dan Guzman" <guzmanda@.nospam-online.sbcglobal.net> wrote in message
> news:u0%23ilqQ%23FHA.4092@.TK2MSFTNGP10.phx.gbl...
> The script would not actually be executed by the text editor, but
> otherwise this is an example of something that would be impractical to
> remove. The actual programs would be WScript and CScript. If removal of
> possibly risky tools is done to protect thd data, then WScript and CScript
> would have to be removed also, which would make all scripts useless. HTML
> scripting capability would also have to be removed.
>
> I think that perormance is not a typical security matter. Performance
> considerations such as this make the problem much more complicated. In
> those situations where elimination of possible performance problems
> require a security solution different from other security solutions, I
> think that the benefits would not justify the cost. I think that
> performance problems should not be a primary duty of security and is
> especially outside the scope of my project.
>
> I do not know if this application's login provides a different security
> context; I am not aware of that, but it is worth investigating.
> If the application provides the ability to execute a macro during or
> immediately following an application, is it possible that the security
> context could be changed then? I realize that this might not work for this
> particular application, so I am asking only if it might work.
> Perhaps it is possible to write a program that changes the security
> context then executes the application, but that would be impractical if it
> requires a separate login. I need to learn about SQL Server's roles before
> deciding to use a solution such as this.
> SQL Server's roles seem to be the prefered solution and I will read the
> article you specify before I ask any questions about roles.
>|||"Dan Guzman" <guzmanda@.nospam-online.sbcglobal.net> wrote in message
news:%23E$%23Noz%23FHA.1676@.TK2MSFTNGP09.phx.gbl...
> I'm not sure I understand what you mean by 'macro'. If you are referring
> to SQL script and the script is run by the app immediately after each
> database connection, such an approach might allow you to enable an
> application role. AFAIK, other 'macro' techniques would require separate
> accounts.
What I meant by macro is that the application (optionally) calls something,
which can be a script, when it gets logged in; therefore the macro is
executed once per execution.
After thinking about it, I realized that that probably won't work, since the
applicaton probably accesses the database prior to the execution of the
login macro.
Artisan a security risk that should be removed from the system, or is it
more effective to use the security provided by SQL Server? I think that
removal of the database utilities is unnecessary, but I have been asked to
develop software that finds the software and optionally removes it.
One reason why removal of the utilities has negligent value is that software
such as that can easily be used from other media and/or can be installed. I
know there are ways to limit use and installation of software but as far as
I know, there would be only partial security provided by doing that.
I need to learn about SQL Server security. If I am correct about what I say
above, then if I can get suggestions for what to read or read about, then
that would help.Preventing access to database utility software does not in itself provide
data security. One can write and execute a script like the one below using
only a text editor.
Set conn = CreateObject("ADODB.Connection")
conn.Open _
"Provider=SQLOLEDB;" & _
"Data Source=MyServer;" & _
"Integrated Security=SSPI;" & _
"Initial Catalog=MyDatabase;"
conn.Execute "DELETE FROM MyTable"
Of course, the user (Windows authenticated account in this example) must
have the appropriate SQL permissions in order to successfully execute such a
script and that is why attention to database security is important.
That said, it is often desirable to discourage ad-hoc SQL access to
production databases using database tools and utilities. Consider a
non-technical user with the database object permissions needed in order to
use an application. With a separate reporting tool, the user could easily
access the database from outside the application and cause blocking or other
performance problems with a poorly formed query. This is one reason why it
is common to create a separate database for end-user reporting and provide
users with the tools needed to do their job.
Applications sometimes use an application login or role to provide data
access under a security context other than the end user. This approach
provides users with the database permissions needed to use the app yet
prevents adhoc access from outside the context of the application unless the
user's own login has been granted the access and permissions.
> I need to learn about SQL Server security. If I am correct about what I
> say above, then if I can get suggestions for what to read or read about,
> then that would help.
For starters, check out 'Managing Security' topic in the Books Online. If
you don't have the doc installed, you can find it online at
http://msdn.microsoft.com/library/d...>
ity_05bt.asp
Hope this helps.
Dan Guzman
SQL Server MVP
"Sam Hobbs" <samuel@.social.rr.com_change_social_to_socal> wrote in message
news:e2EmgVP%23FHA.1332@.tk2msftngp13.phx.gbl...
> Are database utilities, such as Crystal Designer, SQL client tools, and DB
> Artisan a security risk that should be removed from the system, or is it
> more effective to use the security provided by SQL Server? I think that
> removal of the database utilities is unnecessary, but I have been asked to
> develop software that finds the software and optionally removes it.
> One reason why removal of the utilities has negligent value is that
> software such as that can easily be used from other media and/or can be
> installed. I know there are ways to limit use and installation of software
> but as far as I know, there would be only partial security provided by
> doing that.
> I need to learn about SQL Server security. If I am correct about what I
> say above, then if I can get suggestions for what to read or read about,
> then that would help.
>|||"Dan Guzman" <guzmanda@.nospam-online.sbcglobal.net> wrote in message
news:u0%23ilqQ%23FHA.4092@.TK2MSFTNGP10.phx.gbl...
> Preventing access to database utility software does not in itself provide
> data security. One can write and execute a script like the one below
> using only a text editor.
> Set conn = CreateObject("ADODB.Connection")
> conn.Open _
> "Provider=SQLOLEDB;" & _
> "Data Source=MyServer;" & _
> "Integrated Security=SSPI;" & _
> "Initial Catalog=MyDatabase;"
> conn.Execute "DELETE FROM MyTable"
The script would not actually be executed by the text editor, but otherwise
this is an example of something that would be impractical to remove. The
actual programs would be WScript and CScript. If removal of possibly risky
tools is done to protect thd data, then WScript and CScript would have to be
removed also, which would make all scripts useless. HTML scripting
capability would also have to be removed.
> it is often desirable to discourage ad-hoc SQL access to production
> databases using database tools and utilities. Consider a non-technical
> user with the database object permissions needed in order to use an
> application. With a separate reporting tool, the user could easily access
> the database from outside the application and cause blocking or other
> performance problems with a poorly formed query. This is one reason why
> it is common to create a separate database for end-user reporting and
> provide users with the tools needed to do their job.
I think that perormance is not a typical security matter. Performance
considerations such as this make the problem much more complicated. In those
situations where elimination of possible performance problems require a
security solution different from other security solutions, I think that the
benefits would not justify the cost. I think that performance problems
should not be a primary duty of security and is especially outside the scope
of my project.
> Applications sometimes use an application login or role to provide data
> access under a security context other than the end user. This approach
> provides users with the database permissions needed to use the app yet
> prevents adhoc access from outside the context of the application unless
> the user's own login has been granted the access and permissions.
I do not know if this application's login provides a different security
context; I am not aware of that, but it is worth investigating.
If the application provides the ability to execute a macro during or
immediately following an application, is it possible that the security
context could be changed then? I realize that this might not work for this
particular application, so I am asking only if it might work.
Perhaps it is possible to write a program that changes the security context
then executes the application, but that would be impractical if it requires
a separate login. I need to learn about SQL Server's roles before deciding
to use a solution such as this.
SQL Server's roles seem to be the prefered solution and I will read the
article you specify before I ask any questions about roles.|||> The script would not actually be executed by the text editor, but
> otherwise this is an example of something that would be impractical to
> remove.
You are, of course, completely correct. I should have said "write using any
text editor and execute using standard OS componenets".
> I think that perormance is not a typical security matter. Performance
> considerations such as this make the problem much more complicated. In
> those situations where elimination of possible performance problems
> require a security solution different from other security solutions, I
> think that the benefits would not justify the cost. I think that
> performance problems should not be a primary duty of security and is
> especially outside the scope of my project.
I included issues related to authorized data access because I don't know the
scope of your security project and these considerations could affect your
security analysis and design. In the broader sense, security includes
taking reasonable precautions to ensure that data are accessible by
authorized users. Some companies also include DR under the security
umbrella.
> If the application provides the ability to execute a macro during or
> immediately following an application, is it possible that the security
> context could be changed then? I realize that this might not work for this
> particular application, so I am asking only if it might work.
> Perhaps it is possible to write a program that changes the security
> context then executes the application, but that would be impractical if it
> requires a separate login. I need to learn about SQL Server's roles before
> deciding to use a solution such as this.
>
I'm not sure I understand what you mean by 'macro'. If you are referring to
SQL script and the script is run by the app immediately after each database
connection, such an approach might allow you to enable an application role.
AFAIK, other 'macro' techniques would require separate accounts.
Hope this helps.
Dan Guzman
SQL Server MVP
"Sam Hobbs" <samuel@.social.rr.com_change_social_to_socal> wrote in message
news:O8AvMGo%23FHA.272@.TK2MSFTNGP09.phx.gbl...
> "Dan Guzman" <guzmanda@.nospam-online.sbcglobal.net> wrote in message
> news:u0%23ilqQ%23FHA.4092@.TK2MSFTNGP10.phx.gbl...
> The script would not actually be executed by the text editor, but
> otherwise this is an example of something that would be impractical to
> remove. The actual programs would be WScript and CScript. If removal of
> possibly risky tools is done to protect thd data, then WScript and CScript
> would have to be removed also, which would make all scripts useless. HTML
> scripting capability would also have to be removed.
>
> I think that perormance is not a typical security matter. Performance
> considerations such as this make the problem much more complicated. In
> those situations where elimination of possible performance problems
> require a security solution different from other security solutions, I
> think that the benefits would not justify the cost. I think that
> performance problems should not be a primary duty of security and is
> especially outside the scope of my project.
>
> I do not know if this application's login provides a different security
> context; I am not aware of that, but it is worth investigating.
> If the application provides the ability to execute a macro during or
> immediately following an application, is it possible that the security
> context could be changed then? I realize that this might not work for this
> particular application, so I am asking only if it might work.
> Perhaps it is possible to write a program that changes the security
> context then executes the application, but that would be impractical if it
> requires a separate login. I need to learn about SQL Server's roles before
> deciding to use a solution such as this.
> SQL Server's roles seem to be the prefered solution and I will read the
> article you specify before I ask any questions about roles.
>|||"Dan Guzman" <guzmanda@.nospam-online.sbcglobal.net> wrote in message
news:%23E$%23Noz%23FHA.1676@.TK2MSFTNGP09.phx.gbl...
> I'm not sure I understand what you mean by 'macro'. If you are referring
> to SQL script and the script is run by the app immediately after each
> database connection, such an approach might allow you to enable an
> application role. AFAIK, other 'macro' techniques would require separate
> accounts.
What I meant by macro is that the application (optionally) calls something,
which can be a script, when it gets logged in; therefore the macro is
executed once per execution.
After thinking about it, I realized that that probably won't work, since the
applicaton probably accesses the database prior to the execution of the
login macro.
Subscribe to:
Posts (Atom)