Re: getting login name in 4GL
Posted in 1996
I'm not in anyway a UNIX expert. But what is wrong with just using what is
returned from the whoami command. To have control you could even set some
var SYSUSERID='whoami' at the SYSTEM DEFAULT LOGIN SHELL.
-------------------------------------------------------------------------
Cheryl Kendricks
Internet:cherylk@prod1.jcdc.doleta.gov
OR
cherylk@gwysmtp.jcdc.doleta.gov
DTSI, Inc. Voice: 1-800-598-5008
Database Administrator - DOL Job Corps San Marcos, Texas
------------------------------------------------------------------------
On Fri, 10 May 1996, Tim Schaefer wrote:
} Mike Segel wrote:
} > In UNIX, the current username is stored in $LOGNAME. LOGNAME is a read
} > only shell variable. I tested this for /bin/ksh and /bin/sh. You cannot
} > change this variable, hence it should be considered reliable. LOGNAME
} > represents the user name of the login account.
} >
} I tried it too, and just changed it to whatever I wanted. I spawned a
} Bourne shell from a Korn shell, and the changed $LOGNAME came along with
} it. I had done a "export LOGNAME=foofoo", and the new shell adopted
} this new LOGNAME.
}
} It still bugs me to use an environment variable, and to say you "can't"
} change it is not 100% in UNIX. The UNIX I tested it on is 88/Open
} Certified, but I guess that doesn't mean $LOGNAME is secure. So it remains
} a weak link. But maybe on certain UNIX machines this doesn't happen.
} When we finally get to the "unified" UNIX, maybe then I can trust it.
}
} >>
} > Informix, when the front end starts, gets the effective UID and user
} > name.It does not use any
} > of the shell variables. I just tested this. First I tried to change all
} > the variables I could.
} > Informix still picked my login name correctly.
} >
}
} OK. Good. I still don't trust it. :-)
}
} > I then ran a setuid program I had written. This program changes the
} > effective uid of the user and execs a shell.
} >
}
} I couldn't test this today, maybe next week.
}
} > From the shell I called dbaccess and ran the SQL statement. It picked up
} > the username of the user I set myself to. The variable $LOGNAME still
} > represented me.
} >
} > So if you want the Login Name use $LOGNAME. If you want to see what the
} > effective user id running your program, use the "global" username.
} >
}
} Cool. But test it on YOUR machine FIRST to see if it's secure.
}
} > IMHO- I'd trust Informix on this one. (God. Imagine me saying that ;-)
} > For you to do this, you would need to exec a shell, get the UID, then
} > do a lookup against the passwd file.
} >
}
} Which is to say for security reasons, it's a possible weak link.
}
} > All really simple C function calls, but you will have to write the
} > runner, load and link it to your app. I'd say a select statement is
} > much easier.
} >
}
} The bottom line is to test it as you've done, then proceed.
}
} What platform did you run your tests on?
}
} > -Mikey
} > "Hey wadda ya expect? Another great tip from your uncle lou."
} > #include<std.disclaimer.h>
}
} --
} \\\\|//
} (6 6)
} ==============================---o00--(_)--00o---============================
} Tim Schaefer tschaefe@encore.com tschaefe@shadow.net
} Encore Computer Corp http://www.shadow.net/~tschaefe
} =============================================================================
}