Re: Security issue
Posted in 1997
Sorry if I have been confusing. :-(
According to one of the Informix Training guide which I do not have on-hand,
but just a few photocopy pages. One can use (I am _not_ exactly sure how it
works)
Step-1
------
create role foobar;
grant mary to foobar;
Step-2
------
[For every table in database]
revoke all tablename from public;
grant select on tablename to foobar;
front-end
--------
Then, when mary perform a
set role foobar
then she can have only select rights on these tables.
And for most users, there should have been a
grant update on tablename to usergroup-whatever-you-name-it
Good thing is when you add a user, just 'grant newuser to usergroup'.
But when a new table is added, then you have to do the above again.
Anyone are using this feature?
Chris
Daniel Wright (dw420@airmail.net) wrote:
: I'm not sure I followed everything you were asking, but I think you want
: to know how to manage update privileges for given tables (or sets of
: tables) based upon a users "role".
: I am unaware of any capability of Informix assigning users to groups
: which have certain characteristics (although I know such a thing exists
: in some other database engines), but even if this ability does not
: exist, you could certainly simulate it by writing scripts to add a user
: and depending on what "role" you assign them to (via an environment
: variable or whatever), they could be granted proper permissions.
: I'd be curious to know if anyone else thought that any user other than
: 'informix' should belong to the 'informix' group. I can't think of why
: this should be necessary or advisable, and my instinct tells me doing so
: would be a dangerous thing (Then again, many times this problem is
: circumvented by telling everyone the informix password [which inevitably
: in organizations like that something inane, like "informix1"].)