Re: Tell me about your Informix Production System
Posted in 1996
Tom Best [Bentley] wrote: > > If you are running Informix Online in a production system, > what is the typical setup for ANSI-compliant databases? > > The issue I'm concerned about here is the fact that an > ANSI-compliant database requires references to a table to > be qualified with the owner of the table (unless you are > the owner). What do people do in a production > situation... have everyone use the same userid??... create > synonyms in each account to point to the actual qualified > table name??... submit all SQL with the fully-qualified > 'owner'.tablename?? > > Any thoughts/experiences are appreciated. This is a fun one. Lets say that you have a lot of temp users. Sales clerks, DSRs, etc .... From a UNIX sysadmin, this is a nightmare. Create a set of user ids which match what functions they will perform. Manager runs the Manager App. Clerk runs the Clerk App. God, well he's root so it don't matter. ;-) Anyways you get the idea. One user per application. Now, as the users log in, they either hit a menu before the startup of the application, or the first screen of the application. There they are required to enter an ID and a password. You now control the database of user ids. You can set it up so that only managers can modify the user table. You can use the crypt functions to encrypt and decrypt user passwords, so that if someone were to see the data in the table, they can't make any use of it. After verification, the ID is stored in a GLOBAL variable. Any auditing will be based on this ID rather than the USER, or both. Trying to create all thoses synonyms will be a nightmare. As the UNIX system admin on a project which has similar problems, I am advocating this solution. Can anyone think of some holes in it? -Mikey