Re: row level security
Posted in 1998
On Fri, 7 Aug 1998 08:59:30 -0400, in article <6qeu3h$a51$1@supernews.com>, "mud-flap" <NOSPAM_gjspielman@datacorp.com> wrote: >Give each customer their own VIEW, with a WHERE clause that limits them to >looking at rows that have their particular customer id. Of course you have >"customize" your SELECT statements, so that they use the right VIEW based on >the current user - and make sure you give GRANTS at the VIEW level, not the >TABLE level. This works for us.\\ That'd work fine except that he says he doesn't have flexibility over database design or front end. Sounds like he was looking at it from a grant/revoke perspective which won't do it. > >jsmith wrote in message <35CA7FF1.1ACC@hotmail.com>... >>Hi: >> >>We have an inventory-database of our customers, and an application that >>will help them view their inventory. Intially, security was not an >>issue, and therefore one customer could look up the inventory of >>another. Now we would like to restrict access to data based on the >>userid. >> >>How can I accomplish row-level security? Unfortunately I do not have a >>whole lotta flexibility in terms of database design or the front-end. >> >>Any information helps. Thanks in advance. >> >>John > -- for i in databasix primenet ; do ; gburnore@$i ; done --------------------------------------------------------------------------- How you look depends on where you go. --------------------------------------------------------------------------- Gary L. Burnore | '۳'''''''ۺ''''''''''۳ | '۳'''''''ۺ''''''''''۳ DOH! | '۳'''''''ۺ''''''''''۳ | '۳ 3 4 1 4 2 '' 6 9 0 6 9 '۳ spamgard(tm): zamboni | Official Proof of Purchase ===========================================================================