Re: Naive (?) question: Restricting access to CREATE DATABASE
Posted in 1997
>I do not want regular users to be able to create databases.
>How can I achive this?
I don't know of an easy way. There are several mechanisms, though,
depending on how complex you wish to make your task.
1. Write your own pre-processor to parse SQL statements and pass
them through to the engine. This is far easier than it sounds. Just
use a unix filter to generate an error whenever a "regular" user
passes the CREATE DATABASE statement. Then lock your users out of
dbaccess, ISQL, etc.
2. Educate your users not to do that, or teach them to do it in an
appropriate dbspace. This is the DBA's job, and they can either leave
it up to the DBA or learn enough about DBA issues to do it responsibly.
Usually, there are just a few "power users" who want to do this, and
they can be educated fairly well.
3. Write a script that periodically checks for unauthorized databases,
drops them, and mails you a notice and an explanation of why that's
bad to the user.
In the "old days" we DBAs just kept the users constrained within an
application, and controlled what they did via programs. Problems
such as this one are, I fear, simply a natural outgrowth of where the
state of the art is today.
Good luck,
___________________________________________________________
Clem Akins (aka clem@informix.com) <- NEW ACCOUNT!
Informix Software, Inc (Standard disclaimers apply)
International Technical Support
Last seen: Palo Duro Canyon, heart of the Texas Panhandle