Home > SQL Server News > Step 6: Don't expose interfaces that create dynamic SQL to the end user
SQL Server News:
EMAIL THIS

Step 6: Don't expose interfaces that create dynamic SQL to the end user

By Serdar Yegulalp, Contributor
13 May 2005 | SearchSQLServer.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Dynamic SQL -- stored procedures that build other stored procedures, for instance -- can be a big boon. There are some problems that cannot be solved any other way except by dynamically generating SQL, either inside the database itself or through a program that talks to it. That said, if you do this, be sure to take extra steps to abstract the users from such things so that there is no way they can create poisoned code.

One example of this would be passing the name of a table to be dropped or modified through a stored procedure. Unless you ensure that the table name cannot be specified by the user directly (or even indirectly), you're asking for trouble, especially if later down the line the database is not talking to the same user interface code. This can poison not only your data, but also the relational structure of your database itself, and the damage may not even show up until it's far too late.


ENSURING DATA INTEGRITY IN SQL SERVER

 Home: Introduction
 Step 1: Back up, optimize and enable safety features
 Step 2: Segregate data aggressively into files and filegroups
 Step 3: Consider using implicit transactions
 Step 4: Be careful how you enforce internal referential integrity through triggers
 Step 5: Use constraints and relationships to keep out bad data
 Step 6: Don't expose interfaces that create dynamic SQL to the end user
 Step 7: Use a "check-in/check-out" mechanism for contested data

ABOUT THE AUTHOR:   
Serdar Yegulalp
Serdar Yegulalp is editor of the Windows Power Users Newsletter. Check it out for the latest advice and musings on the world of Windows network administrators -- and please share your thoughts as well!
Copyright 2005 TechTarget


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



SQL Administration: SQL Security, SQL Backup, SQL Server Performance
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2005 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts