Oracle FAQ | Your Portal to the Oracle Knowledge Grid |
Home -> Community -> Usenet -> c.d.o.server -> Re: Adding some random characters to Oracle password
Alan wrote:
>
>> > Have all security permissions established by roles and only assign a
>> > to a role inside the application. >> >> >> Just out of interest, and ignoring for the moment that it is roles that
>> granted to a user and not the other way around: how do you propose this >> should work? You mean the application grants roles on log on? And then >> presumably it revokes roles on log-off? And if the user crashes out and >> doesn't log off cleanly?? >> >> Of course, you have to do the revoking bit, because otherwise your user >> would continue to possess the security rights associated with the role,
>> could therefore exercise them by hacking into the back-end directly. >> >> And how would the application know what role to grant to which user? Are
>> proposing to duplicate the database's entire set of user-role grants at
>> application level? >> >> HJR
Scalability is just one concern. What happens if the secret ID and password ever get discovered?
> And, yes, this allows the _developers_ to "administer" data security,
> but in this particular situation, that's the way we want it.
Whatever suits you, I guess. But it doesn't sound to me like that would suit the original poster.
Regards
HJR
Received on Wed Oct 27 2004 - 15:31:27 CDT