Có phải người dùng tạo ra người dùng và người dùng có thể kết nối với nhau không?


8

Tôi không gặp vấn đề gì, nhưng tôi nhận thấy rằng nếu tôi cấp quyền cơ sở dữ liệu cho hiệu trưởng không tồn tại trong cơ sở dữ liệu, quyền đó sẽ hiển thị trong sys.database_permissions nhưng người dùng không thể kết nối với cơ sở dữ liệu (như mong đợi). Nếu tôi sau đó grant connectvới người dùng, mọi thứ đều ổn. Điều đó làm tôi tự hỏi nếu create usergrant connectcó chức năng tương đương. Đó là, là có bất cứ điều gì khác mà create userlàm thế grant connectkhông?

Câu trả lời:


9

Bạn không thể cấp quyền cơ sở dữ liệu cho hiệu trưởng máy chủ: trước tiên bạn cần tạo hiệu trưởng cơ sở dữ liệu, đây là điều bạn có thể đã thực hiện.

Những gì bạn đang đề cập đến là thiếu các đặc quyền CONNECT cho hiệu trưởng GUEST, có khả năng bị thu hồi bởi một DBA khôn ngoan. Khi đặc quyền CONNECT không được cấp rõ ràng cho hiệu trưởng cơ sở dữ liệu, nó sẽ thừa hưởng sự cho phép từ người dùng khách.

Đây là một kịch bản repro có thể giúp bạn hiểu cách mọi thứ hoạt động:

-- create a test database
CREATE DATABASE testPermissions;
GO

USE testPermissions;
GO

-- revoke CONNECT permissions from users that 
-- are not granted CONNECT explicitly or
-- do not inherit the permission from server
-- or database roles.
-- this is considered a security best practice
REVOKE CONNECT FROM GUEST;
GO

-- create a test table
CREATE TABLE someTable (
    someColumn int
);
GO

-- insert some values
INSERT INTO someTable VALUES (1);
GO

-- create a login, AKA server principal
-- this login has NO PERMISSIONS on the database
CREATE LOGIN testlogin WITH PASSWORD=N'aVeryLongPasswordNobodyWillEverGuess', CHECK_POLICY = OFF
GO


-- if you try to grant database permissions 
-- to a login you get an error
GRANT SELECT TO testlogin;
GO

-- Msg 15151, Level 16, State 1, Line 1
-- Cannot find the user 'testlogin', because it does not exist or you do not have permission.

-- if you create a database user you are creating
-- a link between a database principal and
-- a server principal with the "FOR LOGIN" clause
CREATE USER testUser FOR LOGIN testLogin;
GO

-- now if you grant some permissions to the 
-- database principal you won't get any errors
GRANT SELECT TO testUser;
GO

-- you can now see that the database principal
-- has been granted some permissions
SELECT pe.class_desc
    ,OBJECT_NAME(pe.major_id) AS target_object_name
    ,pe.permission_name
    ,pr.name AS grantee
    ,pr.type_desc
FROM sys.database_permissions AS pe
LEFT JOIN sys.database_principals AS pr
    ON pe.grantee_principal_id = pr.principal_id
WHERE pr.name = 'testUser';
GO


-- class_desc  target_object_name  permission_name  grantee   type_desc
-- ----------- ------------------- ---------------- --------- ----------
-- DATABASE    NULL                SELECT           testUser  SQL_USER


-- If you try to connect as the "testUser" database principal
-- you will get an error, as it doesn't have CONNECT privileges
EXECUTE AS USER = 'testUser';
GO

-- Msg 916, Level 14, State 1, Line 1
-- The server principal "testlogin" is not able to access the database "testPermissions" under the current security context.

-- Now grant the CONNECT privilege
GRANT CONNECT TO testUser;
GO

-- If you try to connect as testUser things
-- will now work as expected
EXECUTE AS USER = 'testUser';
GO

USE testPermissions
GO

-- the select permissions are already granted:
-- the query works
SELECT *
FROM someTable;

REVERT;
GO
Khi sử dụng trang web của chúng tôi, bạn xác nhận rằng bạn đã đọc và hiểu Chính sách cookieChính sách bảo mật của chúng tôi.
Licensed under cc by-sa 3.0 with attribution required.