GRANT SELECT in Informix on RedHat 6.2
Posted in 2000
Topics: Server Administration, Security, Permissions & Auditing
This is related to an earlier post regarding the delivery of tabled
data to a web page using a CGI script.
However, the user 'nobody" owns the process that is running the
script. And to put a GRANT CONNECT ... and a GRANT SELECT ...
statement inside the CGI script is counter-intuitive, since that winds
up with user 'nobody' (the owner of the web server process) granting
access to himself, when he doesn't own the database. It doesn't make
sense. But more to the point, it doesn't work either.
So I did a GRANT CONNECT to 'nobody', as in:
GRANT CONNECT TO 'nobody'under the "STARTI dbaccess" text interface.
Notice I didn't specify a table. dbaccess reported a syntax error when
I tried. Informix had no problem with the above syntax, though.
Another statement I wrote was to grant select privelages to 'nobody',
as in:
GRANT SELECT ON names TO 'nobody'
And the table "names" does exist in the database I opened.
Informix had big problems with that. In my text editor (which dbaccess
spawned after the error), the problem it pointed to was the keyword
"GRANT". Aaaarghhh!!!
So, how do I grant access to a user (even PUBLIC wouldn't hurt) either
in a CGI script or on the informix "dbaccess" interface?
Paul King
Hi Paul,
you have to user the 'AS grantor' syntax if you are not the owner of the
table ! Only the owner can grant rights.
Even the DBA cannot change a privilege unless that DBA originally granted
the privilege! (RTFM)
cu
Dirk
Paul King schrieb:
> This is related to an earlier post regarding the delivery of tabled
> data to a web page using a CGI script.
>
> However, the user 'nobody" owns the process that is running the
> script. And to put a GRANT CONNECT ... and a GRANT SELECT ...
> statement inside the CGI script is counter-intuitive, since that winds
> up with user 'nobody' (the owner of the web server process) granting
> access to himself, when he doesn't own the database. It doesn't make
> sense. But more to the point, it doesn't work either.
>
> So I did a GRANT CONNECT to 'nobody', as in:
> GRANT CONNECT TO 'nobody'> under the "STARTI dbaccess" text interface.
>
> Notice I didn't specify a table. dbaccess reported a syntax error when
> I tried. Informix had no problem with the above syntax, though.
>
> Another statement I wrote was to grant select privelages to 'nobody',
> as in:
> GRANT SELECT ON names TO 'nobody'
> And the table "names" does exist in the database I opened.>
> Informix had big problems with that. In my text editor (which dbaccess
> spawned after the error), the problem it pointed to was the keyword
> "GRANT". Aaaarghhh!!!
>
> So, how do I grant access to a user (even PUBLIC wouldn't hurt) either
> in a CGI script or on the informix "dbaccess" interface?
>
> Paul King