Re: Grant / Revoke on IDS 7.3
Posted in 2003
Topics: Security, Permissions & Auditing, Versions, Editions & End-of-Life
Pentti Tiet'v'inen wrote:
> Hello
>
> I'm confused with the grant / revoke statements. I have executed following
> lines to my database:
>
> GRANT ALL ON mytable TO PUBLIC;
> GRANT ALL ON mytable TO quest;
> REVOKE INSERT,DELETE,UPDATE ON mytable FROM quest;
Yes, you are confused. The first statement will grant full access to
mytable to all users, so the next two commands are redundant.
> However user quest can do anything to the table mytable.
Correct. User PUBLIC is like another user name but representing all users.
So you still have ALL permissions granted to all users.
> Must I explicitely name all users who are allowed to do something?
Yes. You can either grant and revoke at the global level (all users) or at
the user level. If you choose the user level, then you must grant as well
as revoke for all users explicitly.
> I think the normal situation
> is that all users are allowed to do all operations and only special users
> are restricted. What is the easiest way to set some restrictions to user
> quest and allow all other users have full control to tables?
Then you need to grant all to those users that are allowed to do all
operations, and revoke from user quest.
You might also want to look at roles, although they are not much different
in operation, but might make admin a little easier.
Cheers,
--
Mark.
+----------------------------------------------------------+-----------+
| Mark D. Stock mailto:mdstock@MydasSolutions.com |//////// /|
| Mydas Solutions Ltd http://MydasSolutions.com |///// / //|
| +-----------------------------------+//// / ///|
| |We value your comments, which have |/// / ////|
| |been recorded and automatically |// / /////|
| |emailed back to us for our records.|/ ////////|
+----------------------+-----------------------------------+-----------+
sending to informix-list
Mark D. Stock wrote: > Pentti Tiet'v'inen wrote: > >> I'm confused with the grant / revoke statements. > > Yes, you are confused. With someone who cares? -- Ciao, The Obnoxious One "Ogni uomo mi guarda come se fossi una testa di cazzo"