Re: User privilege
Posted in 1997
Pralay Dutta Gupta wrote: > > Hi informixers! > > Does anybody know whether it's possible to grant data based > privileges to users of On-line 7.10 UD1 ( isql version 6.02 UC1 ) ? > > To be more explicit, let me say, I've got two groups of users; both > using the same tables. Now, I want to grant privileges to one group > only on the data which they're in charge of. In other words, I would > like to grant row level privileges. Pralay, what you have just requested is possible trhough a view or through stored procedures. Views: 1. Create the table and revoke all privileges on thgat table from both groups of users. 2. Create view1 as a query where columnx = 1 or whatever data setup you have. Similarly, create view2 as a query where columnx = 2. 3. Grant privileges on view1 to group1 people and grant same privs on view2 to group2 people. The app may have to figure out which view to work on based on the user's group affiliation. Stored Procedures: 1. Create the table and revoke all privileges on thgat table from both groups of users. (Sounds familiar) 2. Write a stored procedure owned by a user who HAS privileges on the table. The procedure checks who is running it (select user..) and fetches the data. It examines the data and checks if this user is supposed to be accessing this row. If not, raise exception -746. 3. Grant both groups of users execute privilege on the procedure. The app must use 'execute procedure' to get at the data. -- -- Jake (Lost in thought and won't ask for directions) . . _..-'( )`-.._ ./'. '||\\\\. }\\_/{ .//||` .`\\. ./'.|'.'||||\\\\|.. )o o( ..|//||||`.`|.`\\. ./'..|'.|| |||||\\`````` \\,@,/ ''''''/||||| ||.`|..`\\. ./'.||'.|||| ||||||||||||. ||| .|||||||||||| ||||.`||.`\\. /'|||'.|||||| ||||||||||||{ | }|||||||||||| ||||||.`|||`\\ '.|||'.||||||| ||||||||||||{ | }|||||||||||| |||||||.`|||.` '.||| ||||||||| |/' ``\\||`` | ''||/'' `\\| ||||||||| |||.` |/' \\./' `\\./ \\!|\\ /|!/ \\./' `\\./ `\\| V V V }' `\\ /' `{ V V V \\ \\ \\ V / / / +-----------------------------------------------------------+ | Impeccable Logic: A thought process which successfully | | resists chicken bites | +-----------------------------------------------------------+