note 46925 added to function.mssql-query
| From: | roger4a45 at yahoo dot es | Date: | Wed, 27 Oct 2004 21:15:56 +0000 |
| Subject: | note 46925 added to function.mssql-query | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-79215@lists.php.net to get a copy of this message | ||
Using Aplication Role with PHP
Introduction
Aplication Role is a Microsoft SQL Server 2000 feature that allow to make control what
"source" use your data. It means that you can allow select, inset or update operation from
your PHP code and deny it from and ODBC source, Microsoft Access or any kind of application that
want to use your data.
Scenario:
Imagina you have a DAtabase named MYDB. This DB has three table. TABLEA, TABLEB and TABLEC. Imagine
that your user named 'nemesis' can access to TABLEA from anywhere but you want that from
table B and C access from your PHP code.
Follow this steps
[From your MSSQL Administrator]
1 -. From your Database MYDB create a new role (Standard Role). Insert this user inside this role.
2 -. Edit permisions and deny any operation at TABLEB and TABLEC.
3 -. Create a new Role (Aplication Role). For intance it named 'myaccess' with a password
'anypassword'.
4 -. Edit permisions and allow any operation you wish at TABLEB and TABLEC
[From your source] (I don't include any control errors to simplify source)
$s = mssql_connect('MYSERVER','nemesis','nemesispassword');
$b = mssql_select_db('MYDB',$s);
//This one activate application role. Any user permision are
//ignored. User permision are override with application role
// permisions.
$query = "EXEC sp_setapprole 'myaccess', 'anypassword'";
$b = mssql_query($query);
$result = mssql_query('SELECT * FROM TABLEB,$s);
[...]
Note: If you kill "$query = ..." you will find out that SELECT fails. If you insert that
line $quey will be succeed. Now, nemesis only can take data from TABLEB and TABLEC through your PHP
code. If he/She try to use that data through ODBC driver then he can not do it.
NOte: Application role drops when you make a mssql_close.
----
Manual Page -- http://www.php.net/manual/en/function.mssql-query.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+46925
Delete -- http://master.php.net/manage/user-notes.php?action=delete+46925&report=yes
Reason: bad code -- http://master.php.net/manage/user-notes.php?action=delete+46925&report=yes&reason=bad+code
Reason: spam -- http://master.php.net/manage/user-notes.php?action=delete+46925&report=yes&reason=spam
Reason: useless example -- http://master.php.net/manage/user-notes.php?action=delete+46925&report=yes&reason=useless+example
Reason: contains commercial links -- http://master.php.net/manage/user-notes.php?action=delete+46925&report=yes&reason=contains+commercial+links
Reason: useless note -- http://master.php.net/manage/user-notes.php?action=delete+46925&report=yes&reason=useless+note
Reject -- http://master.php.net/manage/user-notes.php?action=reject+46925&report=yes
Search -- http://master.php.net/manage/user-notes.php