Description
cross db ownership chaining permits ownership chains across databases when the required conditions hold. Permission checks on a referenced object can be skipped when the referring and referenced objects have the same owner and chaining applies, potentially enabling unintended data access.
Cloud SQL deprecates this flag for all SQL Server versions and does not permit newly setting it to on. For existing enabled instances, check dependencies before removing it or setting it to off.
Potential impact
- Someone able to change objects in one database may gain unintended access to another database’s data.
- Disabling chaining without checking dependencies can break cross-database operations.
Remediation
- Review cross-database calls and ownership before removing existing
cross db ownership chainingor setting it tooff. - Provide necessary access through explicit least privileges or a supported alternative such as signed stored procedures. Test legitimate workflows and rejection of unwanted access.
Examples
These excerpts compare part of the instance settings. Use a supported engine version and SQL Server machine type, and supply var.sql_server_tier and omitted required inputs. Changing this flag does not require the engine-version change shown in the examples. The before setting of on is historical and is not a setting to apply to a new instance today.
Before
resource "google_sql_database_instance" "db" {
name = "sqlserver-instance"
database_version = "SQLSERVER_2017_EXPRESS"
region = "us-central1"
settings {
database_flags {
name = "cross db ownership chaining"
value = "on"
}
}
}
After
resource "google_sql_database_instance" "db" {
name = "sqlserver-instance"
database_version = "SQLSERVER_2019_STANDARD"
region = "us-central1"
settings {
tier = var.sql_server_tier
database_flags {
name = "cross db ownership chaining"
value = "off"
}
}
}
Explanation:
- Before: The historical configuration enables cross-database ownership chaining. It does not unconditionally grant access to every database.
- After: The flag is disabled. Required cross-database operations still need appropriate permissions.