4GL code and IDS roles
Posted in 1999
The scenario: I4GL 6.05UD1, OnLine 7.24, AIX 4.1.5
The problem: understanding the relationship between the
engine's concept of roles and 4GL.
Trying to set up some simple roles, basically a read-only role
and a do-anything role for some applications. Using roles
seemed like a clean way to do this with a minimum of 4GL
coding.
Executing "set role rolename" with dbaccess from the shell
in a startup shell script will work correctly - i.e. it errors
out if the user is not granted the role.
fglpc works 'correctly' - I cannot even compile 4GL programs
referring to database tables without select permission on
them.
So I thought, what if a clever user just cd's to the directory
where the .4gi s are and tries to run the program from the
command line using fglgo?
Only way to stop this is to check roles in the 4GL. I can
prepare/execute SQL statements which check sysroleauth and
sysroles just fine ( valid results are returned ). However,
after 'set role $role' is executed, a select statement against
a given table will fail. If I 'model' the same steps in dbaccess,
it works. The select statement is executed from a separate
function in a module which is 'linked' into the .4gi.
Anyone else encounter this or find an approach which works?
TIA,
--
Bruce Thelen, e-group bthelen@seanet.com