Re: Pathname for SPERFORM
Posted in 1994
Several people have commented that they like the fact that the current directory is searched before DBPATH in a development environment. So do I. For development, we have been starting DBPATH with ".:" to force "." to be searched first (not realizing until now that it would have been anyway). However, for production I want to be able to create an access path that does not include any directories to which end-users have access, or as a minimum are not writable by them. As it stands now, if a user can learn or guess a form or ACE report name, they can create a replacement with the same name in the current directory, and the production application will use it regardless of how DBPATH is set. I don't know if I'd go so far as to call this a security hole, but it has the potential for being one. Perhaps "security hernia" would be a good term. :-) I must say I'm still surprised that Informix access works this way under Unix -- especially since the concept of not putting "." in PATH to improve security gets so much publicity. But, I can tell from the tenor of the responses that I'm barking up a dead horse, if I may mix my metaphors as graphically as possible. Perhaps I'll just stick a 'chdir( "/tmp/nowrite" );' or something like that in the start-up code for production applications and move on to something else. Thanks for the replies and follow-up's, Walt. -- Walt Hultgren Internet: walt@rmy.emory.edu (IP 128.140.8.1) Emory University UUCP: {...,gatech,rutgers,uunet}!emory!rmy!walt 954 Gatewood Road, NE BITNET: walt@EMORY Atlanta, GA 30329 USA Voice: +1 404 727 0648