Create MVC attribute to restrict non-AJAX call to the endpoint.


Most of the engineers and database developers often overlooked the importance of database role in database integretiy and security. Often use db_owner during development to make it easy and simple but often carried over in production. This role gives the user full control of the database and can even drop the database.

Follow the steps below to configure database account to use Least Privilege roles.


