【发布时间】:2023-03-04 11:20:01
【问题描述】:
实体数据模型向导说:
此连接字符串似乎包含连接数据库所需的敏感数据(例如密码)。在连接字符串中存储敏感数据可能存在安全风险。您想在连接字符串中包含这些敏感数据吗?
我选择了否,我在我的 Web.config 中发现了以下生成的新连接字符串:
<add name="eMarket_DBEntities" connectionString="metadata=res://*/App_Code.EFModel.csdl|res://*/App_Code.EFModel.ssdl|res://*/App_Code.EFModel.msl;provider=System.Data.SqlClient;provider connection string="data source=.\sqlexpress;initial catalog=eMarket_DB;user id=sa;multipleactiveresultsets=True;application name=EntityFramework"" providerName="System.Data.EntityClient;" />
也在 Web.config 中:
<entityFramework>
<defaultConnectionFactory type="System.Data.Entity.Infrastructure.SqlConnectionFactory, EntityFramework" />
如何以及在哪里最好将密码一次性传递为 EF 的默认值?
【问题讨论】:
标签: c# asp.net sql-server vb.net entity-framework