Re: How is ID validated
Posted in 1997
>Date: Wed, 20 Aug 1997 13:10:12 -0700 >From: jvemo@cyberspace.com (Jon C Vemo) >X-Informix-List-Id: <list.16072> > >I have a question. I'm writing a utility to allow a non-DBA user to execute >database grant/revoke statements. I assumed that the engine used UID >to validate the user for DBA priv's, but this doesn't seem to be the case >(my utility successfully sets the UID to that of user informix). > >Does anyone know how/or what the engine uses to validate a user as >an owner or DBA?? There are a couple of answers. (1) If the program uses CONNECT and specifies the username and password, that's what the database uses as the user's ID. (2) Failing that, it uses the *real* UID, not the effective UID. Under version 5 and earlier systems, this was unavoidable because the sqlexec or sqlturbo process was a setuid root executable, and therefore the only way of identifying who ran the program was via the real UID. I suspect that the version 6 and later systems could have switched to using the effective UID but didn't for reasons of backward compatability. Under version 5 and earlier systems, programs had to be setuid root and then had to force the real UID to the required value for the change in UID to be effective. Yours, Jonathan Leffler (johnl@informix.com) #include <witticism.h>