Re: Informix security questions
Posted in 1997
In article <345E3F4C.654A@bloomberg.com>, "Art S. Kagel" <kagel@bloomberg.com> writes >James Woodger wrote: >> >> I have two basic security questions about Informix: >> >> 1. Is it true that if a user has execute permission on a stored proc, >> then the stored proc will be allowed to perform any table reads or >> updates (regardless of the original user's security profile). In other >> words, stored procedures are not "held back" by the initiating users' >> security level. > >Yes. Think of the SP's permissions and ownership like an SUID program. I thought that was only true if you did CREATE DBA PROCEDURE... rather than CREATE PROCEDURE... >You can use Stored Procedures and permissions to restrict access to a >tables data. > >> 2. Does Informix support specifying security down to the column level? > >Yes. > >Art S. Kagel -- David Williams