Translating with DrWatson… this can take a few seconds the first time.
This is a genuine, complex translation. DrWatson protects commands, error codes, and log output while naturally translating the surrounding text. It’s translated once and saved.
chuan lu asked how to make some tables read-only even for the DBA, since privileges cannot be revoked from oneself and HDR/RSS read-only was unsuitable (version 11.50). Marcus Haarmann suggested Security Policies; Henri Cujass suggested upgrading and user/role rules or trigger functions; Frank Yunyao Qu suggested triggers raising an exception. No confirmed solution.
Auto-generated by Claude from the posts below — may be imperfect; read the full thread.
chuan lu — source: IBM Community (ConnectedCommunity.org) Informix forum
Hi,
The develop DBA want to change some tables to read only , include the DBA himself can't update/insert/delete those record also. Do anyone have experience how to implement it in informix? The document told me "You cannot revoke privileges from yourself."
Any suggestion are welcome.
------------------------------
chuan lu
------------------------------
↪ replying to chuan lu
Marcus Haarmann — source: IBM Community (ConnectedCommunity.org) Informix forum
chuan lu — source: IBM Community (ConnectedCommunity.org) Informix forum
HI,
I have read those document about table privileges in version 11.50。With such requirement I can't use HDR/RSS read only feature, because some table still need to be modified. Customer want to change a part tables to read only.
Do anyone have additional suggestion? thanks for your time
------------------------------
chuan lu
------------------------------
↪ replying to chuan lu
Henri Cujass — source: IBM Community (ConnectedCommunity.org) Informix forum
Hi Chuan,
My first recommendation - migrate to 14.10 or 15.0 . The next, to think about your user and role concept - levels, rules, HDR secondary updateable?
And maybe if you need some special handling of update/insert, you can use a trigger function to implement your business/security policy depending on the user. If you decide to use rules, you can set them with sysdbsopen procedure for each user.
Best Regards, Henri
------------------------------
Henri Cujass
leolo IT, CTO
Germany
IBM Champion
henri.cujass@leolo.com
------------------------------
↪ replying to chuan lu
Frank Yunyao Qu — source: IBM Community (ConnectedCommunity.org) Informix forum
A option of raising exception by using update/insert/delete triggers should help.
Thanks
Frank
Your privacy choices
We use strictly necessary cookies to make this site work. With your
consent we’d also use optional cookies for analytics and marketing. You can accept all,
reject all, or choose. Read our Cookie Policy.