difference between all and public
Posted in 2007
Topics: Security, Permissions & Auditing
Hi all, i have a function and i gave permission to all like that: grant execute on function my_function to all and now pepole can use the function - but not all and i try this: grant execute on function my_function to public And what is now? Can realy all the people use the function ? I can not understand this ! - How is not in the group all ? And what is solve of my problem - I want that realy all in the office can use my function. Thanks a lot.
On Jun 11, 12:28 pm, "hoffi...@googlemail.com" <hoffi...@googlemail.com> wrote: > Hi all, > > i have a function and i gave permission to all > like that: grant execute on function my_function to all > > and now pepole can use the function - but not all Informix does NOT have a defined group 'all'. 'Public' is the pseudo user you grant permissions to in Informix is you REALLY want anyone with connect privs to be able to access an object., so this is WAD (Works As Designed). Art S. Kagel > and i try this: grant execute on function my_function to public > > And what is now? > Can realy all the people use the function ? > > I can not understand this ! - How is not in the group all ? > > And what is solve of my problem - I want that realy all in the office > can use my function. > > Thanks a lot.
hoffiman@googlemail.com wrote: > Hi all, > > i have a function and i gave permission to all > like that: grant execute on function my_function to all > > and now pepole can use the function - but not all > > and i try this: grant execute on function my_function to public > > And what is now? > Can realy all the people use the function ? > > I can not understand this ! - How is not in the group all ? > > And what is solve of my problem - I want that realy all in the office > can use my function. > > Thanks a lot. > Your confusion may come from the fact that since the users are external, Informix does not validate their existence when you do the grants. When you did "grant execute to all" you stored the execute privilege to a user or role (like a group) called "all". The users you say that could execute it were either users who already could or DBAs which can by default... "public" is different and has the meaning you meant with "all". You should revoke the execute privilege from "all". Regards.