I keep seeing post saying that you can hide parameters and pass the values
through a querystring by clearing out the prompt string and unchecking prompt
user. However, when I try this i get an error saying the propery is read
only. Any Suggestions.
--
Thanks,
Danny BaderI too get this error if I leave the parameter prompt blank. I keep hearing
that you have to install SP1 to make this go away. I have SP2 installed and
it still happens. Does SP2 not have the SP1 fixes in it also? If not, is it
okay to install SP1 even though I already have SP2 installed?
Robert|||I have SP2 installed as well.
--
Thanks,
Danny Bader
"Robert RVRK" wrote:
> I too get this error if I leave the parameter prompt blank. I keep hearing
> that you have to install SP1 to make this go away. I have SP2 installed and
> it still happens. Does SP2 not have the SP1 fixes in it also? If not, is it
> okay to install SP1 even though I already have SP2 installed?
> Robert|||Hi Danny,
I think I might have found the solution. Instead of blanking out the
parameter prompt, enter a space for the parameter prompt. Supposedly this
will work when you view the report in the report viewer (but it won't in the
IDE, so don't give up until you've tried it in the viewer). I am going to go
try myself now...
Robert|||> through a querystring by clearing out the prompt string and unchecking prompt
> user.
Nope. Just clear the prompt string and DON'T uncheck the prompt user option.
--
Please mark the correct/helpful answers!|||you can do by following steps:
1. check "allow null"
2. Clear the prompt string
3. select "none" for default value
4. in report manager, check "prompt user", but clear the prompt string
so, this parameter will not appear in parameter panel
and you can pass value to this parameter through URL
"Danny Bader" wrote:
> I keep seeing post saying that you can hide parameters and pass the values
> through a querystring by clearing out the prompt string and unchecking prompt
> user. However, when I try this i get an error saying the propery is read
> only. Any Suggestions.
> --
> Thanks,
> Danny Bader
Showing posts with label string. Show all posts
Showing posts with label string. Show all posts
Friday, February 24, 2012
hiding parameters
Hiding parameter passed through query string
I'm using Reporting Servicves for SQL Server 2000 and I've embedded a
ReportViewer control in an ASP.NET page. The reports I link to all require a
sensitive parameter value and I have been passing that through using the
query string. Unfortunately, the entire URL of the report--including the
parameter in the query string--is visible in the source for the page, and I
don't want the user to see this for security purposes.
Is there a way to hide this? I'm open to any and all suggestions.
Thanks,
MarkSearch the group on encryption - use System.Security.Cryptography package
I just repeat myself from a previous posting:
"Parameter's encryption is a key to solve your problem.
The simplest ( but not the only) way is:
1.create your own parameters collection pages (forms).
2. encrypt user input using a permanent or temporary encryption key.
3. Reference encryption assembly in your report designer.
4. use a decryption routine in your custom code akin
"=Code.Library.Decrypt(Parameters!account_id);" by retrieving an encryption
key used in step 2.
By using this approach even a simplest parameter will be totally un
guessable, because even a single digit will be encrypted to something like
"bHZiajB4TGpBdU1"
"
"Mark" <Mark@.discussions.microsoft.com> wrote in message
news:98599DF6-C0E8-418A-A573-8293EEE98E13@.microsoft.com...
> I'm using Reporting Servicves for SQL Server 2000 and I've embedded a
> ReportViewer control in an ASP.NET page. The reports I link to all require
> a
> sensitive parameter value and I have been passing that through using the
> query string. Unfortunately, the entire URL of the report--including the
> parameter in the query string--is visible in the source for the page, and
> I
> don't want the user to see this for security purposes.
> Is there a way to hide this? I'm open to any and all suggestions.
> Thanks,
> Mark|||For RS 2000 you can use web services. There is really no way using URL
integration to hide it from the source. You can hide it from the page being
displayed but if they go View, Source they will see it.
In VS 2005 there are two new controls that work with RS 2005. They use web
services under the covers, not URL integration. You do have to have RS 2005.
Note that you can upgrade to RS 2005 while leaving the database at 2000
(that is what I have done). You do need a SQL Server 2005 license for this
however.
My suggestion is if security is important then you use the new controls.
One other option, put the parameters in a database table and then pass the
primary key to the table and have a dataset extracting the parameters.
This does make things more complicated but it is a version independent
solution (if you can convince management to upgrade to RS 2005). Note what I
said about upgrading. Sometimes it is easier to get permission to upgrade
reporting services than it is to upgrade a SQL Server database.
Bruce Loehle-Conger
MVP SQL Server Reporting Services
"Mark" <Mark@.discussions.microsoft.com> wrote in message
news:98599DF6-C0E8-418A-A573-8293EEE98E13@.microsoft.com...
> I'm using Reporting Servicves for SQL Server 2000 and I've embedded a
> ReportViewer control in an ASP.NET page. The reports I link to all require
> a
> sensitive parameter value and I have been passing that through using the
> query string. Unfortunately, the entire URL of the report--including the
> parameter in the query string--is visible in the source for the page, and
> I
> don't want the user to see this for security purposes.
> Is there a way to hide this? I'm open to any and all suggestions.
> Thanks,
> Mark|||Good point. I forgot about doing that.
Bruce Loehle-Conger
MVP SQL Server Reporting Services
"Oleg Yevteyev" <myfirstname001atgmaildotcom> wrote in message
news:OdtQOZxCGHA.1816@.TK2MSFTNGP11.phx.gbl...
> Search the group on encryption - use System.Security.Cryptography package
> I just repeat myself from a previous posting:
> "Parameter's encryption is a key to solve your problem.
> The simplest ( but not the only) way is:
> 1.create your own parameters collection pages (forms).
> 2. encrypt user input using a permanent or temporary encryption key.
> 3. Reference encryption assembly in your report designer.
> 4. use a decryption routine in your custom code akin
> "=Code.Library.Decrypt(Parameters!account_id);" by retrieving an
> encryption
> key used in step 2.
> By using this approach even a simplest parameter will be totally un
> guessable, because even a single digit will be encrypted to something like
> "bHZiajB4TGpBdU1"
> "
>
> "Mark" <Mark@.discussions.microsoft.com> wrote in message
> news:98599DF6-C0E8-418A-A573-8293EEE98E13@.microsoft.com...
>> I'm using Reporting Servicves for SQL Server 2000 and I've embedded a
>> ReportViewer control in an ASP.NET page. The reports I link to all
>> require a
>> sensitive parameter value and I have been passing that through using the
>> query string. Unfortunately, the entire URL of the report--including the
>> parameter in the query string--is visible in the source for the page, and
>> I
>> don't want the user to see this for security purposes.
>> Is there a way to hide this? I'm open to any and all suggestions.
>> Thanks,
>> Mark
>
ReportViewer control in an ASP.NET page. The reports I link to all require a
sensitive parameter value and I have been passing that through using the
query string. Unfortunately, the entire URL of the report--including the
parameter in the query string--is visible in the source for the page, and I
don't want the user to see this for security purposes.
Is there a way to hide this? I'm open to any and all suggestions.
Thanks,
MarkSearch the group on encryption - use System.Security.Cryptography package
I just repeat myself from a previous posting:
"Parameter's encryption is a key to solve your problem.
The simplest ( but not the only) way is:
1.create your own parameters collection pages (forms).
2. encrypt user input using a permanent or temporary encryption key.
3. Reference encryption assembly in your report designer.
4. use a decryption routine in your custom code akin
"=Code.Library.Decrypt(Parameters!account_id);" by retrieving an encryption
key used in step 2.
By using this approach even a simplest parameter will be totally un
guessable, because even a single digit will be encrypted to something like
"bHZiajB4TGpBdU1"
"
"Mark" <Mark@.discussions.microsoft.com> wrote in message
news:98599DF6-C0E8-418A-A573-8293EEE98E13@.microsoft.com...
> I'm using Reporting Servicves for SQL Server 2000 and I've embedded a
> ReportViewer control in an ASP.NET page. The reports I link to all require
> a
> sensitive parameter value and I have been passing that through using the
> query string. Unfortunately, the entire URL of the report--including the
> parameter in the query string--is visible in the source for the page, and
> I
> don't want the user to see this for security purposes.
> Is there a way to hide this? I'm open to any and all suggestions.
> Thanks,
> Mark|||For RS 2000 you can use web services. There is really no way using URL
integration to hide it from the source. You can hide it from the page being
displayed but if they go View, Source they will see it.
In VS 2005 there are two new controls that work with RS 2005. They use web
services under the covers, not URL integration. You do have to have RS 2005.
Note that you can upgrade to RS 2005 while leaving the database at 2000
(that is what I have done). You do need a SQL Server 2005 license for this
however.
My suggestion is if security is important then you use the new controls.
One other option, put the parameters in a database table and then pass the
primary key to the table and have a dataset extracting the parameters.
This does make things more complicated but it is a version independent
solution (if you can convince management to upgrade to RS 2005). Note what I
said about upgrading. Sometimes it is easier to get permission to upgrade
reporting services than it is to upgrade a SQL Server database.
Bruce Loehle-Conger
MVP SQL Server Reporting Services
"Mark" <Mark@.discussions.microsoft.com> wrote in message
news:98599DF6-C0E8-418A-A573-8293EEE98E13@.microsoft.com...
> I'm using Reporting Servicves for SQL Server 2000 and I've embedded a
> ReportViewer control in an ASP.NET page. The reports I link to all require
> a
> sensitive parameter value and I have been passing that through using the
> query string. Unfortunately, the entire URL of the report--including the
> parameter in the query string--is visible in the source for the page, and
> I
> don't want the user to see this for security purposes.
> Is there a way to hide this? I'm open to any and all suggestions.
> Thanks,
> Mark|||Good point. I forgot about doing that.
Bruce Loehle-Conger
MVP SQL Server Reporting Services
"Oleg Yevteyev" <myfirstname001atgmaildotcom> wrote in message
news:OdtQOZxCGHA.1816@.TK2MSFTNGP11.phx.gbl...
> Search the group on encryption - use System.Security.Cryptography package
> I just repeat myself from a previous posting:
> "Parameter's encryption is a key to solve your problem.
> The simplest ( but not the only) way is:
> 1.create your own parameters collection pages (forms).
> 2. encrypt user input using a permanent or temporary encryption key.
> 3. Reference encryption assembly in your report designer.
> 4. use a decryption routine in your custom code akin
> "=Code.Library.Decrypt(Parameters!account_id);" by retrieving an
> encryption
> key used in step 2.
> By using this approach even a simplest parameter will be totally un
> guessable, because even a single digit will be encrypted to something like
> "bHZiajB4TGpBdU1"
> "
>
> "Mark" <Mark@.discussions.microsoft.com> wrote in message
> news:98599DF6-C0E8-418A-A573-8293EEE98E13@.microsoft.com...
>> I'm using Reporting Servicves for SQL Server 2000 and I've embedded a
>> ReportViewer control in an ASP.NET page. The reports I link to all
>> require a
>> sensitive parameter value and I have been passing that through using the
>> query string. Unfortunately, the entire URL of the report--including the
>> parameter in the query string--is visible in the source for the page, and
>> I
>> don't want the user to see this for security purposes.
>> Is there a way to hide this? I'm open to any and all suggestions.
>> Thanks,
>> Mark
>
Sunday, February 19, 2012
Hiding an SQL connection string in an Excel macro
Is there a technique for hiding the SQL connection string (ADO) in an Excel
macro? I think I already know the answer to that question (no), but I'm
just wondering if there's a trick that would accomplish it.
I'm authoring some macros for a client of mine and they need to communicate
with an SQL server account I have with my web hosting company and I
obviously don't want them to know my username and password.
Thanks in advance.
Hi Bob,
From your descriptions, I understood that you would like to "hide" SQL
Connection Strings in your macro to protect your SQL username and password.
Have I understood you? Correct me if I was wrong.
Based on my scope, yes, we are not able to "hide" SQL connection strings
directly, however, I think you could encrypt your macro as a workaround.
You can password protect the VBProject. In VBA, go to the Tools menu,
choose VBA Project Properties, then the Protection tab. There, check the
"Lock Project For Viewing" tab, and assign a password. Note, however, that
there are products available that can defeat the password protection. In
this way, you are able to protect your SQL username and password.
For more information about how to do this in encrypt this in Excel, I would
appreciated if you could create a new thread in the
microsoft.public.excel.programming (BTW, I am not sure whether it is a
managed newsgroup)
Thank you for your patience and corporation. If you have any questions or
concerns, don't hesitate to let me know. We are always here to be of
assistance!
Sincerely yours,
Michael Cheng
Online Partner Support Specialist
Partner Support Group
Microsoft Global Technical Support Center
Get Secure! - http://www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only, many thanks!
macro? I think I already know the answer to that question (no), but I'm
just wondering if there's a trick that would accomplish it.
I'm authoring some macros for a client of mine and they need to communicate
with an SQL server account I have with my web hosting company and I
obviously don't want them to know my username and password.
Thanks in advance.
Hi Bob,
From your descriptions, I understood that you would like to "hide" SQL
Connection Strings in your macro to protect your SQL username and password.
Have I understood you? Correct me if I was wrong.
Based on my scope, yes, we are not able to "hide" SQL connection strings
directly, however, I think you could encrypt your macro as a workaround.
You can password protect the VBProject. In VBA, go to the Tools menu,
choose VBA Project Properties, then the Protection tab. There, check the
"Lock Project For Viewing" tab, and assign a password. Note, however, that
there are products available that can defeat the password protection. In
this way, you are able to protect your SQL username and password.
For more information about how to do this in encrypt this in Excel, I would
appreciated if you could create a new thread in the
microsoft.public.excel.programming (BTW, I am not sure whether it is a
managed newsgroup)
Thank you for your patience and corporation. If you have any questions or
concerns, don't hesitate to let me know. We are always here to be of
assistance!
Sincerely yours,
Michael Cheng
Online Partner Support Specialist
Partner Support Group
Microsoft Global Technical Support Center
Get Secure! - http://www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only, many thanks!
Hiding an SQL connection string in an Excel macro
Is there a technique for hiding the SQL connection string (ADO) in an Excel
macro? I think I already know the answer to that question (no), but I'm
just wondering if there's a trick that would accomplish it.
I'm authoring some macros for a client of mine and they need to communicate
with an SQL server account I have with my web hosting company and I
obviously don't want them to know my username and password.
Thanks in advance.Hi Bob,
From your descriptions, I understood that you would like to "hide" SQL
Connection Strings in your macro to protect your SQL username and password.
Have I understood you? Correct me if I was wrong.
Based on my scope, yes, we are not able to "hide" SQL connection strings
directly, however, I think you could encrypt your macro as a workaround.
You can password protect the VBProject. In VBA, go to the Tools menu,
choose VBA Project Properties, then the Protection tab. There, check the
"Lock Project For Viewing" tab, and assign a password. Note, however, that
there are products available that can defeat the password protection. In
this way, you are able to protect your SQL username and password.
For more information about how to do this in encrypt this in Excel, I would
appreciated if you could create a new thread in the
microsoft.public.excel.programming (BTW, I am not sure whether it is a
managed newsgroup)
Thank you for your patience and corporation. If you have any questions or
concerns, don't hesitate to let me know. We are always here to be of
assistance!
Sincerely yours,
Michael Cheng
Online Partner Support Specialist
Partner Support Group
Microsoft Global Technical Support Center
---
Get Secure! - http://www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only, many thanks!
macro? I think I already know the answer to that question (no), but I'm
just wondering if there's a trick that would accomplish it.
I'm authoring some macros for a client of mine and they need to communicate
with an SQL server account I have with my web hosting company and I
obviously don't want them to know my username and password.
Thanks in advance.Hi Bob,
From your descriptions, I understood that you would like to "hide" SQL
Connection Strings in your macro to protect your SQL username and password.
Have I understood you? Correct me if I was wrong.
Based on my scope, yes, we are not able to "hide" SQL connection strings
directly, however, I think you could encrypt your macro as a workaround.
You can password protect the VBProject. In VBA, go to the Tools menu,
choose VBA Project Properties, then the Protection tab. There, check the
"Lock Project For Viewing" tab, and assign a password. Note, however, that
there are products available that can defeat the password protection. In
this way, you are able to protect your SQL username and password.
For more information about how to do this in encrypt this in Excel, I would
appreciated if you could create a new thread in the
microsoft.public.excel.programming (BTW, I am not sure whether it is a
managed newsgroup)
Thank you for your patience and corporation. If you have any questions or
concerns, don't hesitate to let me know. We are always here to be of
assistance!
Sincerely yours,
Michael Cheng
Online Partner Support Specialist
Partner Support Group
Microsoft Global Technical Support Center
---
Get Secure! - http://www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only, many thanks!
Hiding an SQL connection string in an Excel macro
Is there a technique for hiding the SQL connection string (ADO) in an Excel
macro? I think I already know the answer to that question (no), but I'm
just wondering if there's a trick that would accomplish it.
I'm authoring some macros for a client of mine and they need to communicate
with an SQL server account I have with my web hosting company and I
obviously don't want them to know my username and password.
Thanks in advance.Hi Bob,
From your descriptions, I understood that you would like to "hide" SQL
Connection Strings in your macro to protect your SQL username and password.
Have I understood you? Correct me if I was wrong.
Based on my scope, yes, we are not able to "hide" SQL connection strings
directly, however, I think you could encrypt your macro as a workaround.
You can password protect the VBProject. In VBA, go to the Tools menu,
choose VBA Project Properties, then the Protection tab. There, check the
"Lock Project For Viewing" tab, and assign a password. Note, however, that
there are products available that can defeat the password protection. In
this way, you are able to protect your SQL username and password.
For more information about how to do this in encrypt this in Excel, I would
appreciated if you could create a new thread in the
microsoft.public.excel.programming (BTW, I am not sure whether it is a
managed newsgroup)
Thank you for your patience and corporation. If you have any questions or
concerns, don't hesitate to let me know. We are always here to be of
assistance!
Sincerely yours,
Michael Cheng
Online Partner Support Specialist
Partner Support Group
Microsoft Global Technical Support Center
---
Get Secure! - http://www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only, many thanks!
macro? I think I already know the answer to that question (no), but I'm
just wondering if there's a trick that would accomplish it.
I'm authoring some macros for a client of mine and they need to communicate
with an SQL server account I have with my web hosting company and I
obviously don't want them to know my username and password.
Thanks in advance.Hi Bob,
From your descriptions, I understood that you would like to "hide" SQL
Connection Strings in your macro to protect your SQL username and password.
Have I understood you? Correct me if I was wrong.
Based on my scope, yes, we are not able to "hide" SQL connection strings
directly, however, I think you could encrypt your macro as a workaround.
You can password protect the VBProject. In VBA, go to the Tools menu,
choose VBA Project Properties, then the Protection tab. There, check the
"Lock Project For Viewing" tab, and assign a password. Note, however, that
there are products available that can defeat the password protection. In
this way, you are able to protect your SQL username and password.
For more information about how to do this in encrypt this in Excel, I would
appreciated if you could create a new thread in the
microsoft.public.excel.programming (BTW, I am not sure whether it is a
managed newsgroup)
Thank you for your patience and corporation. If you have any questions or
concerns, don't hesitate to let me know. We are always here to be of
assistance!
Sincerely yours,
Michael Cheng
Online Partner Support Specialist
Partner Support Group
Microsoft Global Technical Support Center
---
Get Secure! - http://www.microsoft.com/security
This posting is provided "as is" with no warranties and confers no rights.
Please reply to newsgroups only, many thanks!
Subscribe to:
Posts (Atom)