Re: webapplication with SQL-server

From: Jeff Cochran (jeff.nospam_at_zina.com)
Date: 07/02/04

  • Next message: Jeff Cochran: "Re: SQL to allow a "no preference (all) choice"
    Date: Fri, 02 Jul 2004 20:03:00 GMT
    
    

    On Fri, 2 Jul 2004 14:22:42 +0200, "Ludo VdB" <ict@vagga.be> wrote:

    >I'm new to ASP. Currently I'm planning to develop a web application for my
    >company. I want to use ASP for the application and use SQL-server as the
    >back-end.
    >
    >I want to enable a userID and password for every user. I also want to
    >specify permissions to parts of the application.
    >
    >I have 2 scenario's for this:
    >
    >I let the application handle the permissions to the different parts. I keep
    >the permissions in a table in the database so the application knows witch
    >user has access to witch part of the application. therefore I will only need
    >one connection to the DB.
    >
    >I let the permissions handle thru the DB. The application passes through
    >password and userID to the DB. For every user who logons to the application,
    >the application will have a connection to the DB.
    >
    >What's the best scenario?
    >Or witch scenario should I use when?

    Neither is best or worst, and assuming you're working with Windows
    accounts in the same Windows domain as your app and server, using
    Windows authentication might be easier for you to manage. I'd suggest
    grouping access levels for convenience, so all users that need access
    to part A would be in a group, part B another group, etc.

    Jeff


  • Next message: Jeff Cochran: "Re: SQL to allow a "no preference (all) choice"

    Relevant Pages

    • RE: What server hardening are you doing these days?
      ... permissions on their data, and Microsoft encourages ISVs to minimize ... I've been able to discuss ACLs and other security issues in Windows with ... Control or DAC (which is what you're referring to by the "stupid ...
      (Focus-Microsoft)
    • Re: Unnown process... 5eplorer.exe
      ... do not remove the cause (a "super"-hidden .dll program) but only remove ... symptom files and registry settings. ... It has all permissions but 'copy' denied to everyone, ... then by using the Windows XP Recovery Console. ...
      (microsoft.public.win2000.general)
    • RE: dcom permissions and vista?
      ... user BLAH with Local Activation and Local Launch permissions. ... Windows Vista indeed do some changes in handling DCOM and you may need to ... Windows Vista introduces the notion of Mandatory Access Labels in security ... Microsoft Online Community Support ...
      (microsoft.public.vc.atl)
    • Re: Passwords on Folders
      ... domain computer [there is also a recovery agent for a domain]. ... > Windows under which those permissions were defined. ... use NTFS on your hard drives so you can then EFS ...
      (microsoft.public.win2000.security)
    • RE: SBS 2003 Outoging Fax Problem w/Error 32028 (Cannot send - fatal error)
      ... 1.Reduce the baud rate of the incoming fax modem and see how it goes. ... Click Permissions and verify that the user attempting to fax has at ... 3.If you have configured the fax client on the Windows XP computer ... On the "Additional Server Types" page, ...
      (microsoft.public.windows.server.sbs)