How to set user privivilge at the application level
Posted in 1999
Topics: Connectivity: ODBC / JDBC / .NET
In our environment, we have an application that requires users have full access privileges (connect, update, delete, select, insert). The application has a security module that handles who can do what. This application runs on HP servers and we have control of the software and tools that make available to users. Increasingly, more and more desk top users with ODBC drivers are beginning to connect to our database directly. In addition to the queries and reports, these users can damage the database, maybe by accident. So what we need is the ability to discriminate the user accessing the database at the application level. i.e. if a user access the database from our application, the database will allow that user to have full access privileges, else it limits that user to do data query only. Many thanks to ideas, suggestions, etc. Ben Truong ben.truong@amd.com
Many ways to do this, here's an easy(ish) one. Make your own user/password table in Informix. Have the application control this table, no one else has any permissions on it. When a user logs in to the application (not directly to Informix) the application does its own checking against the table and connects them as a generic user. Then you revoke most of the priveledges from the OS defined users. Ben Truong (Ben.Truong@amd.com) wrote: : In our environment, we have an application that requires users have full : access privileges (connect, update, delete, select, insert). The : application has a security module that handles who can do what. This : application runs on HP servers and we have control of the software and : tools that make available to users. Increasingly, more and more desk top : users with ODBC drivers are beginning to connect to our database directly. : In addition to the queries and reports, these users can damage the : database, maybe by accident. : So what we need is the ability to discriminate the user accessing the : database at the application level. i.e. if a user access the database from : our application, the database will allow that user to have full access : privileges, else it limits that user to do data query only. : Many thanks to ideas, suggestions, etc. : Ben Truong : ben.truong@amd.com -- Rob Wilson rwilson@ntsource.com