Storing user name and password in same database with other transaction data is good idea from application architecture point of view?Where do you store your salt strings?How should I ethically approach user password storage for later plaintext retrieval?Storing user and password in a databaseHow can bcrypt have built-in salts?Storing database passwords of users on a database. Is using the application user password as a salt for encryption a good approach?SPA best practices for authentication and session managementJWT (JSON Web Token) automatic prolongation of expirationToken Based Authentication in ASP.NET CoreIs it safe to store a hashed password in the same database with the rest of the dataWhat could be a decent workflow to a user registration application to store password?

What is the meaning of "of trouble" in the following sentence?

What would happen to a modern skyscraper if it rains micro blackholes?

How is the claim "I am in New York only if I am in America" the same as "If I am in New York, then I am in America?

How can I fix this gap between bookcases I made?

Banach space and Hilbert space topology

New order #4: World

Infinite past with a beginning?

How does one intimidate enemies without having the capacity for violence?

How to make payment on the internet without leaving a money trail?

Is there a familial term for apples and pears?

Chess with symmetric move-square

Copycat chess is back

I’m planning on buying a laser printer but concerned about the life cycle of toner in the machine

XeLaTeX and pdfLaTeX ignore hyphenation

Can Medicine checks be used, with decent rolls, to completely mitigate the risk of death from ongoing damage?

Circuitry of TV splitters

Prevent a directory in /tmp from being deleted

Is there really no realistic way for a skeleton monster to move around without magic?

DOS, create pipe for stdin/stdout of command.com(or 4dos.com) in C or Batch?

How do I create uniquely male characters?

Why is the design of haulage companies so “special”?

Why has Russell's definition of numbers using equivalence classes been finally abandoned? ( If it has actually been abandoned).

How did the USSR manage to innovate in an environment characterized by government censorship and high bureaucracy?

Do airline pilots ever risk not hearing communication directed to them specifically, from traffic controllers?



Storing user name and password in same database with other transaction data is good idea from application architecture point of view?


Where do you store your salt strings?How should I ethically approach user password storage for later plaintext retrieval?Storing user and password in a databaseHow can bcrypt have built-in salts?Storing database passwords of users on a database. Is using the application user password as a salt for encryption a good approach?SPA best practices for authentication and session managementJWT (JSON Web Token) automatic prolongation of expirationToken Based Authentication in ASP.NET CoreIs it safe to store a hashed password in the same database with the rest of the dataWhat could be a decent workflow to a user registration application to store password?






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















I am working on the ASP.NET Web API Core 2.2 application which is already developed. We are using SQL Server 2017 as a data base.
Front end is Angular6.
My WEB API application is linked with Entity Framework for storing and retrieving data.
When I am debugging the application even after giving wrong password for the application, I can read data from all tables in the database. Even if I give correct password then also before generating token I can see data from all the tables.




I would like to know if it is glitch in the application?



Also is it good idea to store User ID and passwords along with other
application related data in the same database?



If user id and passwords are in same database the how can we restrict
accessing other tables before user is getting authenticated as the
application should be able to know the difference between user table
and other transaction tables











share|improve this question
























  • Can any one help me in this?

    – Shardul
    Mar 8 at 5:58

















0















I am working on the ASP.NET Web API Core 2.2 application which is already developed. We are using SQL Server 2017 as a data base.
Front end is Angular6.
My WEB API application is linked with Entity Framework for storing and retrieving data.
When I am debugging the application even after giving wrong password for the application, I can read data from all tables in the database. Even if I give correct password then also before generating token I can see data from all the tables.




I would like to know if it is glitch in the application?



Also is it good idea to store User ID and passwords along with other
application related data in the same database?



If user id and passwords are in same database the how can we restrict
accessing other tables before user is getting authenticated as the
application should be able to know the difference between user table
and other transaction tables











share|improve this question
























  • Can any one help me in this?

    – Shardul
    Mar 8 at 5:58













0












0








0








I am working on the ASP.NET Web API Core 2.2 application which is already developed. We are using SQL Server 2017 as a data base.
Front end is Angular6.
My WEB API application is linked with Entity Framework for storing and retrieving data.
When I am debugging the application even after giving wrong password for the application, I can read data from all tables in the database. Even if I give correct password then also before generating token I can see data from all the tables.




I would like to know if it is glitch in the application?



Also is it good idea to store User ID and passwords along with other
application related data in the same database?



If user id and passwords are in same database the how can we restrict
accessing other tables before user is getting authenticated as the
application should be able to know the difference between user table
and other transaction tables











share|improve this question
















I am working on the ASP.NET Web API Core 2.2 application which is already developed. We are using SQL Server 2017 as a data base.
Front end is Angular6.
My WEB API application is linked with Entity Framework for storing and retrieving data.
When I am debugging the application even after giving wrong password for the application, I can read data from all tables in the database. Even if I give correct password then also before generating token I can see data from all the tables.




I would like to know if it is glitch in the application?



Also is it good idea to store User ID and passwords along with other
application related data in the same database?



If user id and passwords are in same database the how can we restrict
accessing other tables before user is getting authenticated as the
application should be able to know the difference between user table
and other transaction tables








entity-framework security authentication asp.net-web-api2 sql-server-2017






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Mar 8 at 5:59







Shardul

















asked Jan 10 at 15:21









ShardulShardul

709




709












  • Can any one help me in this?

    – Shardul
    Mar 8 at 5:58

















  • Can any one help me in this?

    – Shardul
    Mar 8 at 5:58
















Can any one help me in this?

– Shardul
Mar 8 at 5:58





Can any one help me in this?

– Shardul
Mar 8 at 5:58












0






active

oldest

votes












Your Answer






StackExchange.ifUsing("editor", function ()
StackExchange.using("externalEditor", function ()
StackExchange.using("snippets", function ()
StackExchange.snippets.init();
);
);
, "code-snippets");

StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "1"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













draft saved

draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f54131799%2fstoring-user-name-and-password-in-same-database-with-other-transaction-data-is-g%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes















draft saved

draft discarded
















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid


  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.

To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f54131799%2fstoring-user-name-and-password-in-same-database-with-other-transaction-data-is-g%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Save data to MySQL database using ExtJS and PHP [closed]2019 Community Moderator ElectionHow can I prevent SQL injection in PHP?Which MySQL data type to use for storing boolean valuesPHP: Delete an element from an arrayHow do I connect to a MySQL Database in Python?Should I use the datetime or timestamp data type in MySQL?How to get a list of MySQL user accountsHow Do You Parse and Process HTML/XML in PHP?Reference — What does this symbol mean in PHP?How does PHP 'foreach' actually work?Why shouldn't I use mysql_* functions in PHP?

Compiling GNU Global with universal-ctags support Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 23, 2019 at 23:30 UTC (7:30pm US/Eastern) Data science time! April 2019 and salary with experience The Ask Question Wizard is Live!Tags for Emacs: Relationship between etags, ebrowse, cscope, GNU Global and exuberant ctagsVim and Ctags tips and trickscscope or ctags why choose one over the other?scons and ctagsctags cannot open option file “.ctags”Adding tag scopes in universal-ctagsShould I use Universal-ctags?Universal ctags on WindowsHow do I install GNU Global with universal ctags support using Homebrew?Universal ctags with emacsHow to highlight ctags generated by Universal Ctags in Vim?

Add ONERROR event to image from jsp tldHow to add an image to a JPanel?Saving image from PHP URLHTML img scalingCheck if an image is loaded (no errors) with jQueryHow to force an <img> to take up width, even if the image is not loadedHow do I populate hidden form field with a value set in Spring ControllerStyling Raw elements Generated from JSP tagds with Jquery MobileLimit resizing of images with explicitly set width and height attributeserror TLD use in a jsp fileJsp tld files cannot be resolved