Subject | Re: [firebird-support] Important security question |
---|---|
Author | Nando Dessena |
Post date | 2003-09-18T06:28:16Z |
Boguslaw,
B> By the way : how is presented database in error messages in this situation :
B> by the short alias name or by the full path ? I have strange suspicion that
B> full path in presented to user which may broke security, but I may be wrong.
I don't follow you. If you get an error while trying to create a
database, you specified the connection string containing the path, so
who cares if it bounces back to you?
In addition, presenting full path of an existing database does not
break security, just obfuscation, or indirection if you prefer.
Aliases are not a security matter, they are all about convenience in
managing connection strings.
Ciao
--
Nando mailto:nandod@...
B> By the way : how is presented database in error messages in this situation :
B> by the short alias name or by the full path ? I have strange suspicion that
B> full path in presented to user which may broke security, but I may be wrong.
I don't follow you. If you get an error while trying to create a
database, you specified the connection string containing the path, so
who cares if it bounces back to you?
In addition, presenting full path of an existing database does not
break security, just obfuscation, or indirection if you prefer.
Aliases are not a security matter, they are all about convenience in
managing connection strings.
Ciao
--
Nando mailto:nandod@...