Re: getting login name in 4GL
Posted in 1996
Nils.Myklebust@ccmail.telemax.no wrote: > > I side with the one who created a dummy table with one row only > and used that. > We allways need such a table with system releated information > anyway so this is no problem. Ours isn't called dummy of course, > and we store application version information, several codes used > for different purposes and even the engine version, whether transactions > are in use and other stuff here. Although the engine info can be gleaned from > system information available when the database is opened, that may > change. Any application can more easily read this from a table, and when > using ODBC (and later possibly with Java) this info isn't as easily > available without this table. > > Also I don't quite grasp Tim Schaefer's problem with trusting the user > name returned from a select to the database. If that isn't correct than > all my grants of access rights are in vain, aren't they? > Or do I miss something here? > Nils, I responded to Joe Lumbley's post with this. But it may not have hit all news-servers, including mine. The original question of getting the login id is perhaps ( in my little world at least ) involved with a two-fold process: 1 - get the login from the OS ( for me most likely UNIX ) 2 - get more info about a user from a look-up table These two processes are distinct enough, and can be managed quite simply, which I think we are all probably in agreement on. My little point was to make sure, hopefully without a doubt that the user id to query-on in a look-up table is really the one I want. The OS should be able to provide this accurately. From there, I go to a table to look-up detail information about a user, as you suggest. If you have a lot of users in a rather large company, and there is always a turnover of personnel, you can set up a cron to update the user-detail-table with the most current information nightly from a password file. This seems to be quite reliable. The use of the USER variable is quite unreliable, as well as just using data base information solely without checking the OS for the user id. Sometimes it's not just users, but investors and auditors we must satisfy. Cheers, Tim -- \\\\|// (6 6) ==============================---o00--(_)--00o---============================ Tim Schaefer tschaefe@encore.com tschaefe@shadow.net Encore Computer Corp http://www.shadow.net/~tschaefe =============================================================================