Re: Database security
Posted in 1991
Path: emory!swrinde!cs.utexas.edu!natinst!uudell!bigtex!texsun!cronkite.Central.Sun.COM!jethro!srfrogs!myro From: myro@srfrogs.Corp.Sun.COM (Michael Meyers) Newsgroups: comp.databases.informix Message-ID: <6170@jethro.Corp.Sun.COM> Date: 10 Oct 91 17:05:04 GMT Sender: news@jethro.Corp.Sun.COM Reply-To: myro@srfrogs.Corp.Sun.COM Organization: Sun Microsystems In article 503@rand.mel.cocam.oz.au, shaneb@auzodt3.mel.cocam.oz.au (Shane Booth writes: > > Does anyone know a way to allow users to run a 4GL application that inserts > and deletes from a database, but to disallow the users from altering the data > by running isql? Here we run Informix-4GL version 4.00.UC1 for Sco Unix. > > Thanks for any help, > Shane Booth > shaneb@auzodt3.mel.cocam.oz.au Informix permissions are kept by the backend not the frontend, thus there is no way to give access to a user under 4GL and not SQL. What _may_ work is to turn on the setuid bit on for 4gl code. If the theory holds up, then all changes made to the database will be made by one user, which may ruin other parts of your database security. For example it will be next to impossible to track who made what changes, and it will make any individual permissions useless. Might be worth a try????? Mike Meyers