Re: Informix security questions
Posted in 1997
Jack Parker wrote:
>
> At 09:59 AM 11/3/97 -0500, you wrote:
> >I have two basic security questions about Informix:
> >
> >1. Is it true that if a user has execute permission on a stored
proc,
> >then the stored proc will be allowed to perform any table reads or
> >updates (regardless of the original user's security profile). In
> other
> >words, stored procedures are not "held back" by the initiating
users'
> >security level.
>
> This is an advantage. A properly written stored procedure allows the
> user
> to execute with the SPs authors permissions - even though they have
> none
> themselves. This means you can lock them out from all of the tables
> and
> force them to use the SP to manipulate them.
>
> >2. Does Informix support specifying security down to the column
> level?
>
> Yes. It's stored in syscolauth.
>
> GRANT permission (column_list) ON table TO user_list
Just remember it's only for SELECT, UPDATE and REFERENCES.
That is:
GRANT {SELECT|UPDATE|REFERENCES}(column_list) ON table TO user_list
Cheers,
--
Mark.
+----------------------------------------------------------+-----------+
|Mark D. Stock - Informix SA http://www.informix.com |//////// /|
|mailto:mdstock@informix.com FAQ http://www.iiug.org |///// / //|
| +-----------------------------------+//// / ///|
| Tel: +27 11 807 0313 |If it's slow, the users complain. |/// / ////|
| Fax: +27 11 807 2594 |If it's fast, the users keep quiet.|// / /////|
|Cell: +27 83 250 2325 |Therefore, "No news: travels fast"!|/ ////////|
+----------------------+-----------------------------------+-----------+