Re: Can this work - soft code SP table name in parameter?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: David Portas (REMOVE_BEFORE_REPLYING_dportas_at_acm.org)
Date: 01/21/05


Date: Fri, 21 Jan 2005 08:01:13 -0000


> peripheral tables - there's no danger anyone can run the
> SP 'manually' or anything, due to the appropriate SQL user
> being the only person with permission to execute it.

Wrong. Did you read the article that Alejandro posted? Dynamic SQL forces
you to grant user-level access to tables, thereby destroying the key
security benefit of stored procedures. You should have a very good reason
for compromising security in this way: to save yourself a minute's work
cutting and pasting four SPs is not a good reason in my book. Dynamic SQL
should be a last resort.

-- 
David Portas
SQL Server MVP
--


Relevant Pages

  • RE: Backups have Shadow Copy Problems
    ... Active backup destination: File ... Reason: The process cannot access the file because it is being used by ... Warning: Unable to open "C:\Documents and Settings\Administrator\Local ... Warning: Unable to open "C:\Program Files\Microsoft SQL ...
    (microsoft.public.windows.server.sbs)
  • RE: Backups have Shadow Copy Problems
    ... recovery model of the SQL Server database to Simple. ... Warning: Unable to open "C:\Program Files\Microsoft SQL ... Reason: The process cannot access the file because it is being used by ... Backup completed on 2/14/2006 at 3:39 PM. ...
    (microsoft.public.windows.server.sbs)
  • [Full-Disclosure] RE: SQL Slammer doing the rounds again?
    ... I was assuming that this was the only reason the poor netadmin ... the web designers and their choices; I can't speak to the issues ... Security Business Unit ... SQL Slammer doing the rounds again? ...
    (Full-Disclosure)
  • Re: Backup erros
    ... You may have a SQL ... Error 800423f4 appears in the backup log file when you back up a volume by ... > Reason: The process cannot access the file because it is being used by> another process. ...
    (microsoft.public.windows.server.sbs)
  • RE: Backups have Shadow Copy Problems
    ... Warning: Unable to open "C:\Program Files\Microsoft SQL ... Reason: The process cannot access the file because it is being used by ... Backup completed on 2/14/2006 at 3:39 PM. ...
    (microsoft.public.windows.server.sbs)