Re: ODBC SQL security issues???
Posted in 1994
Mark Bixby writes: -> ... ->3) You've created database logon IDs & passwords, and you've granted read/write ->access to the tables each user needs to access via the application. But what ->do you do about Joe or Jane Poweruser who goes down to their neighborhood ->software store and buys an ODBC-compliant SQL query/update tool, and they go ->and modify tables in harmful ways not permitted by the applications ->themselves? Mark, Informix stored procedures offer a way around this last problem. If you always call a stored procedure to perform inserts, updates, and deletes, you can use the dba feature to limit permissions. Create the stored procedure as a dba privileged user. Then you can allow your users to run the stored procedure with dba privileges for the duration of the procedure, without having to give your users access to the underlying tables. I hope this helps a little. Regards, - Cathy -------------------------------------------------------------------------------- Cathy Kipp e-mail: ckipp@vth1.vth.colostate.edu Phone: (303) 491-1294 Colorado State University Veterinary Teaching Hospital Fax: (303) 491-1205 Coming in late summer, from Prentice Hall, my new book: PROGRAMMING INFORMIX: A STEP BY STEP APPROACH (ISBN: 0-13-149394-9)