Fix User vs Login for granting exec to "xp_cmdshell" #3720
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR fixes #3719 .
These two changes regard Item # 3 under "Permissions" on the "xp_cmdshell" page. That paragraph is currently as follows:
GRANTstatement includes reference to "login" when logins cannot be granted permissions on schema-bound objects.The final sentence of that paragraph states that the login (being granted the permission) needs to be mapped to a user in the
masterdatabase. Yes, a user does need to exist inmaster, but again, this has nothing to do with logins:master, then it would work to grant permission to the login (assuming different names between login and user such that this is a meaningful distinction). { see example 1 }The following example shows:
master, still can't be granted permission.The following test shows that a user does not even need to have an associated login in order to be granted permission to use
xp_cmdshell:Take care,
Solomon...
https://SqlQuantumLift.com/
https://SqlQuantumLeap.com/
https://SQLsharp.com/