Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, February 19, 2012

Allowed Set for All Members

It looks like NULL is treated the same way as an empty set {} for allowed/denied sets.If I use dynamic security by calling to an SSAS stored procedure but I want to allow the users of an admin role to see all members, what should the stored procedure return?It doesn't matter how you set up security - the database administrators (and server administrators too) will always be able to see everything. Security definitions are not even evaluated for them.|||Thank you, Mosha. I understand this. In this case, I was referring to an "application" administrator. So, when I use dynamic security and call down to the application security infrastructure and the application tells me that the user is an application administrator, what do I need to return as a set from the SSAS stored procedure to allow all members?|||Depends on the return type of your sproc. If it is a string - then you can return empty string, and it should be fine. But if your sproc returns AdomdServer.Set, then I don't have very good advice. Obviously returning set of all members for the attribute - i.e. Dim.Attr.Attr.MEMBERS seems the right thing to do, but you may have problems including in sproc hidden members etc. Dimension security itself when it evaluated expression Dim.Attr.Attr.MEMBERS would do the right thing though.|||

I am affraid this doesn't work for me. Given this stored procedure

public static string GetCustomer(bool admin) {

return admin ? String.Empty : "{[Customer].[Customer].&[15]}";

}

String.Empty, "", null don't work. Nor do {[Customer].[Customer].&[15]} or StrToSet('{[Customer].[Customer].&[15]}') although plugging in {[Customer].[Customer].&[15]} in the allowed set expression works. The stored procedure executes succesfully but the server throws the following exception on browse:

The function expects a tuple set expression for the argument. A string or numeric expression was used. The 'Customer attribute in the 'Customer' dimension has a generated dimension security expression that is not valid. What am I doing wrong?

|||

Your sproc looks good. In the allowed set expression you should use the following expression: StrToSet(GetCustomer(admin))

|||

Thanks, Mosha. I was just writing an update when I got your reply. Yes, StrToSet(Extensibility.GetCustomer(false)) works. But StrToSet(Extensibility.GetCustomer(true)) doesn't. I tested with "", String.Empty, or null. So, back to my original question, what should the sp return if I wan't to void the allowed set and allow all members?

|||

Perhaps the following will work for you:

IIF(admin, "", Extensibility.GetCustomer(false))

|||

Yes, but I don't know if the user is admin. I stubbed out the stored procedure for testing purposes only. Recall that the application security layer knows who the user is given the user Windows identity. I would get back a list of the allowed members. But since an admin user has access to all members (of a very large dimension), I would like to short-curcuit the filter. So, if the security layer returns null (or whatever the convention is for admin), it would be faster to nuke the filter as opposed to getting/setting a set with all members.

Hope this makes sense.

|||BTW, IIF(admin, "", Extensibility.GetCustomer(false)) or simply "" don't work too. It looks like the only input that allowed/denied set filters support is a set with no option to set the filter to empty.

Thursday, February 16, 2012

allow direct updates to systemtables

Hi,
I cannot find "allow direct updates to system tables" in security tab of SQL
Server 2005 setting, while BOL addresses that!
Where is it?!
Thanks,
Leila
Leila wrote:
> Hi,
> I cannot find "allow direct updates to system tables" in security tab of SQL
> Server 2005 setting, while BOL addresses that!
> Where is it?!
> Thanks,
> Leila
You cannot do it. Updating system tables was never a good idea anyway.
What is it you are trying to achieve?
David Portas, SQL Server MVP
Whenever possible please post enough code to reproduce your problem.
Including CREATE TABLE and INSERT statements usually helps.
State what version of SQL Server you are using and specify the content
of any error messages.
SQL Server Books Online:
http://msdn2.microsoft.com/library/ms130214(en-US,SQL.90).aspx
|||> I cannot find "allow direct updates to system tables" in security tab of
> SQL Server 2005 setting, while BOL addresses that!
Can you show the URL(s)/article(s) where BOL says this option exists?
|||ms-help://MS.SQLCC.v9/MS.SQLSVR.v9.en/uirfsql9/html/b8a131c7-e7bd-4203-bf26-234f1ebfe622.htm
"Aaron Bertrand [SQL Server MVP]" <ten.xoc@.dnartreb.noraa> wrote in message
news:%23XY46PK8GHA.3740@.TK2MSFTNGP05.phx.gbl...
> Can you show the URL(s)/article(s) where BOL says this option exists?
>
|||Perhaps you have an older version of Books Online? I checked three
computers and could not find that statement on the "Server Properties
(Security Page)" topic. Perhaps it was an omission on first release but has
since been corrected? You may want to ensure you have the most recent
refresh (2006-07-21):
http://www.microsoft.com/technet/pro...ads/books.mspx
"Leila" <Leilas@.hotpop.com> wrote in message
news:%23bs3LUK8GHA.3396@.TK2MSFTNGP04.phx.gbl...
> ms-help://MS.SQLCC.v9/MS.SQLSVR.v9.en/uirfsql9/html/b8a131c7-e7bd-4203-bf26-234f1ebfe622.htm
>
> "Aaron Bertrand [SQL Server MVP]" <ten.xoc@.dnartreb.noraa> wrote in
> message news:%23XY46PK8GHA.3740@.TK2MSFTNGP05.phx.gbl...
>
|||> Perhaps you have an older version of Books Online?
The reference was in the RTM but removed in the BOL refresh
(http://www.microsoft.com/downloads/d...displaylang=en).
Hope this helps.
Dan Guzman
SQL Server MVP
"Aaron Bertrand [SQL Server MVP]" <ten.xoc@.dnartreb.noraa> wrote in message
news:OIvIAZK8GHA.4776@.TK2MSFTNGP02.phx.gbl...
> Perhaps you have an older version of Books Online? I checked three
> computers and could not find that statement on the "Server Properties
> (Security Page)" topic. Perhaps it was an omission on first release but
> has since been corrected? You may want to ensure you have the most recent
> refresh (2006-07-21):
> http://www.microsoft.com/technet/pro...ads/books.mspx
>
>
> "Leila" <Leilas@.hotpop.com> wrote in message
> news:%23bs3LUK8GHA.3396@.TK2MSFTNGP04.phx.gbl...
>

allow direct updates to systemtables

Hi,
I cannot find "allow direct updates to system tables" in security tab of SQL
Server 2005 setting, while BOL addresses that!
Where is it?!
Thanks,
LeilaLeila wrote:
> Hi,
> I cannot find "allow direct updates to system tables" in security tab of S
QL
> Server 2005 setting, while BOL addresses that!
> Where is it?!
> Thanks,
> Leila
You cannot do it. Updating system tables was never a good idea anyway.
What is it you are trying to achieve?
David Portas, SQL Server MVP
Whenever possible please post enough code to reproduce your problem.
Including CREATE TABLE and INSERT statements usually helps.
State what version of SQL Server you are using and specify the content
of any error messages.
SQL Server Books Online:
http://msdn2.microsoft.com/library/ms130214(en-US,SQL.90).aspx
--|||> I cannot find "allow direct updates to system tables" in security tab of
> SQL Server 2005 setting, while BOL addresses that!
Can you show the URL(s)/article(s) where BOL says this option exists?|||ms-help://MS.SQLCC.v9/MS.SQLSVR.v9.en/uirfsql9/html/b8a131c7-e7bd-4203-bf26-
234f1ebfe622.htm
"Aaron Bertrand [SQL Server MVP]" <ten.xoc@.dnartreb.noraa> wrote in mess
age
news:%23XY46PK8GHA.3740@.TK2MSFTNGP05.phx.gbl...
> Can you show the URL(s)/article(s) where BOL says this option exists?
>|||Perhaps you have an older version of Books Online? I checked three
computers and could not find that statement on the "Server Properties
(Security Page)" topic. Perhaps it was an omission on first release but has
since been corrected? You may want to ensure you have the most recent
refresh (2006-07-21):
http://www.microsoft.com/technet/pr...oads/books.mspx
"Leila" <Leilas@.hotpop.com> wrote in message
news:%23bs3LUK8GHA.3396@.TK2MSFTNGP04.phx.gbl...
> ms-help://MS.SQLCC.v9/MS.SQLSVR.v9.en/uirfsql9/html/b8a131c7-e7bd-4203-bf2
6-234f1ebfe622.htm
>
> "Aaron Bertrand [SQL Server MVP]" <ten.xoc@.dnartreb.noraa> wrote in
> message news:%23XY46PK8GHA.3740@.TK2MSFTNGP05.phx.gbl...
>|||> Perhaps you have an older version of Books Online?
The reference was in the RTM but removed in the BOL refresh
(http://www.microsoft.com/downloads/...&displaylang=en).
Hope this helps.
Dan Guzman
SQL Server MVP
"Aaron Bertrand [SQL Server MVP]" <ten.xoc@.dnartreb.noraa> wrote in mess
age
news:OIvIAZK8GHA.4776@.TK2MSFTNGP02.phx.gbl...
> Perhaps you have an older version of Books Online? I checked three
> computers and could not find that statement on the "Server Properties
> (Security Page)" topic. Perhaps it was an omission on first release but
> has since been corrected? You may want to ensure you have the most recent
> refresh (2006-07-21):
> http://www.microsoft.com/technet/pr...oads/books.mspx
>
>
> "Leila" <Leilas@.hotpop.com> wrote in message
> news:%23bs3LUK8GHA.3396@.TK2MSFTNGP04.phx.gbl...
>

allow direct updates to systemtables

Hi,
I cannot find "allow direct updates to system tables" in security tab of SQL
Server 2005 setting, while BOL addresses that!
Where is it?!
Thanks,
LeilaLeila wrote:
> Hi,
> I cannot find "allow direct updates to system tables" in security tab of SQL
> Server 2005 setting, while BOL addresses that!
> Where is it?!
> Thanks,
> Leila
You cannot do it. Updating system tables was never a good idea anyway.
What is it you are trying to achieve?
--
David Portas, SQL Server MVP
Whenever possible please post enough code to reproduce your problem.
Including CREATE TABLE and INSERT statements usually helps.
State what version of SQL Server you are using and specify the content
of any error messages.
SQL Server Books Online:
http://msdn2.microsoft.com/library/ms130214(en-US,SQL.90).aspx
--|||> I cannot find "allow direct updates to system tables" in security tab of
> SQL Server 2005 setting, while BOL addresses that!
Can you show the URL(s)/article(s) where BOL says this option exists?|||ms-help://MS.SQLCC.v9/MS.SQLSVR.v9.en/uirfsql9/html/b8a131c7-e7bd-4203-bf26-234f1ebfe622.htm
"Aaron Bertrand [SQL Server MVP]" <ten.xoc@.dnartreb.noraa> wrote in message
news:%23XY46PK8GHA.3740@.TK2MSFTNGP05.phx.gbl...
>> I cannot find "allow direct updates to system tables" in security tab of
>> SQL Server 2005 setting, while BOL addresses that!
> Can you show the URL(s)/article(s) where BOL says this option exists?
>|||Perhaps you have an older version of Books Online? I checked three
computers and could not find that statement on the "Server Properties
(Security Page)" topic. Perhaps it was an omission on first release but has
since been corrected? You may want to ensure you have the most recent
refresh (2006-07-21):
http://www.microsoft.com/technet/prodtechnol/sql/2005/downloads/books.mspx
"Leila" <Leilas@.hotpop.com> wrote in message
news:%23bs3LUK8GHA.3396@.TK2MSFTNGP04.phx.gbl...
> ms-help://MS.SQLCC.v9/MS.SQLSVR.v9.en/uirfsql9/html/b8a131c7-e7bd-4203-bf26-234f1ebfe622.htm
>
> "Aaron Bertrand [SQL Server MVP]" <ten.xoc@.dnartreb.noraa> wrote in
> message news:%23XY46PK8GHA.3740@.TK2MSFTNGP05.phx.gbl...
>> I cannot find "allow direct updates to system tables" in security tab of
>> SQL Server 2005 setting, while BOL addresses that!
>> Can you show the URL(s)/article(s) where BOL says this option exists?
>|||> Perhaps you have an older version of Books Online?
The reference was in the RTM but removed in the BOL refresh
(http://www.microsoft.com/downloads/details.aspx?FamilyID=BE6A2C5D-00DF-4220-B133-29C1E0B6585F&displaylang=en).
--
Hope this helps.
Dan Guzman
SQL Server MVP
"Aaron Bertrand [SQL Server MVP]" <ten.xoc@.dnartreb.noraa> wrote in message
news:OIvIAZK8GHA.4776@.TK2MSFTNGP02.phx.gbl...
> Perhaps you have an older version of Books Online? I checked three
> computers and could not find that statement on the "Server Properties
> (Security Page)" topic. Perhaps it was an omission on first release but
> has since been corrected? You may want to ensure you have the most recent
> refresh (2006-07-21):
> http://www.microsoft.com/technet/prodtechnol/sql/2005/downloads/books.mspx
>
>
> "Leila" <Leilas@.hotpop.com> wrote in message
> news:%23bs3LUK8GHA.3396@.TK2MSFTNGP04.phx.gbl...
>> ms-help://MS.SQLCC.v9/MS.SQLSVR.v9.en/uirfsql9/html/b8a131c7-e7bd-4203-bf26-234f1ebfe622.htm
>>
>> "Aaron Bertrand [SQL Server MVP]" <ten.xoc@.dnartreb.noraa> wrote in
>> message news:%23XY46PK8GHA.3740@.TK2MSFTNGP05.phx.gbl...
>> I cannot find "allow direct updates to system tables" in security tab
>> of SQL Server 2005 setting, while BOL addresses that!
>> Can you show the URL(s)/article(s) where BOL says this option exists?
>>
>

Monday, February 13, 2012

All users can edit security!

I've been fighting for 2 days trying to figure out how to block general user
s from being able to edit security on reports/folders. I have myself set up
as Content Manager and the groups Everyone and Users set up as Browsers. C
an someone please tell me w
hat I am missing? Thanks.OOPs. Should've put this in Reporting Services area. Sorry.
"BrianW" wrote:

> I've been fighting for 2 days trying to figure out how to block general users from
being able to edit security on reports/folders. I have myself set up as Content Ma
nager and the groups Everyone and Users set up as Browsers. Can someone please tell
me
what I am missing? Thanks.