الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

طريقة تسيير المستخدمين

بدأه kachwahed في 18 مارس 2010 · 3 رد · 1,522 مشاهدة · في قواعد بيانات Microsoft SQL Server
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

بسم الله الرحمن الرحيم

السلام عليكم ورحمة الله

نعلم أن SQL Server يوفر خدمات متقدمة لتسيير مستخدمي قاعدة البيانات وتحديد مستويات صلاحيات كل مستخدم... الخ

لكن العديد من المبرمجين يلجأ بشكل "تقليدي" إلى إنشاء جدول لتخزين أسماء المستخدمين وشفرات (Hash) كلمات السر وحقول للصلاحيات أحيانا أو معلومات أخرى...، مدعين في ذلك كسب المزيد من المرونة والتحكم...

برأيكم؟ أي الطريقتين أفضل، وبم تنصحون؟

شكرا مسبقا.

#2

I assume that in the second method, they use one centeral login with admin privilages and then they try to control what the local user can do and what he can't, right?

In other words, they have a single admin account, they then see if the user is an admin or not based on their logic and decide what can he do and what he can't?

Mohamed Meshref

Software Design Engineer

SQL Server Team

Microsoft Corporation, Redmond HQ

Phone: +1-(425)704-8684

Mobile: +1-(425)445-7386

Email: mmeshref(at)microsoft(dot)com

#3

@Mohamed Moshrif

Thanks for reply

I guess that SQL Server provides a great advantages to protect data, and because most of developers don't mastering SQL Server properly they prefer to create they own user tables and do some tedious jobs!

I should write Arabic, sorry about that.

Regards

#4

First of all, I am Egyptian, so I can understand and read arabic, I just don't have arabic keyboard as I don't live in Egypt

What I am saying that NO ONE SHOULD EVER write his own authentication system, we are going away of using SQL Authentication because of the same reason, too much trouble, and you can secure against everything, and you get Windows Authentication for free, and it's really a very strong and secure system, so why rebuilding the wheel and having more chances of getting into trouble with the increase of your surface area?

I can list you infinite number of reasons of why the system you listed above is un-secure and has a lot of security issues

Mohamed Meshref

Software Design Engineer

SQL Server Team

Microsoft Corporation, Redmond HQ

Phone: +1-(425)704-8684

Mobile: +1-(425)445-7386

Email: mmeshref(at)microsoft(dot)com

مواضيع مشابهة