Re: ODBC and Security
Posted in 1996
Irwin, For a newbie, you certainly come up with good answers! If the OpenLink ODBC driver can control read/write permissions, then that may be a good enough solution. But, does that stop anyone from using another ODBC driver that's more open? I still think my original solution is most secure, which I'll repeat: Setup your users with read-only access to the database. Create one user called "program" which has read/write access. Regardless of the user, the central application connects to the database as user "program", having the password hard coded. In this way, the central application is the only client modifying data. Users can connect using ODBC or anything else using their own id's to query and produce reports. Another advantage of using this method that wasn't mentioned before is the ease of version control. When the database structure changes significantly, requiring a new version of the application, simply change the password for "program". The old version of the application will try to connect using the old password, and fail, while the new version will proceed unrestricted. Of course, the old version shouldn't exist anywhere, but you never know... Irwin Goldstein wrote: >Ok, I'm new to Internet news groups, AND I am comming in the middle of this >discussion, so excuse me if this is off the mark: >It sounds like you are facing the quandry of wanting to give the same user >application access and ad-hoc query access (via ODBC) to the same database. >In "application" mode, updates, deletes, etc. are safe because the >application >controls things, but in the wild and free world of ODBC, where the user may >just decide to open tables in MS Access (or some other ODBC enabled tool), >you definitely do not want users to be able to add, update, delete. >If this is the case, look in to the OpenLink ODBC drivers. OpenLink has many >nice features, including the ability to control read/write permissions by >client IP address, user-id, application name, etc. For example, I have >set up OpenLink to provide read-only access to users of specific PC >apps (Access, Business Objects, etc.) and NO access to any other ODBC apps. >User's who log in to Unix & use 4gl apps user the same log-in which >they use for ODBC log-ins. OpenLink prevents the ODBC connections >from doing anything but reads, while 4gl just uses the database permissions. >Hope this proves useful!