Re: Roles and Security
Posted in 1998
Herb Blacker wrote: > > Here's an interesting problem...we're developing a large OLTP appl. with > a nationwide usage of roughly 4,000 users. We certainly don't want to > 'grant select to public' on this database, so we've developed about 40 > roles with specific permissions. This will handle normal procesing...the > problem comes in the 'ad-hoc' reporting area. We are considering using > PowerSoft's Infomaker as an ad-hoc reporter, but its usage is that a 'user' > logs on, not a 'role'(no way that I know of to issue a 'set role'). > We would like to set up the same sort of 'role' system for ad-hoc reporting > to limit what the user can report on. Anybody got any ideas? I have a shell script that can combine privileges from existing users. I create some pseudo-users which are used as groups of privileges which are then applied to the real users. It doesn't keep an audit trail or anything sophisticated so it wouldn't scale to a very complex system. It just makes managing users' privileges a lot easier. If you are interested I could post it here or if anyone can tell me how, I could offer it to the IIUG. -- Peter Lancashire Information Systems Specialist, Bayer plc Eastern Way, Bury St Edmunds, Suffolk, IP32 7AH, UK Tel: +44-1635-562258, Fax: +44-1635-562281 Mail: Peter.Lancashire.PL1@bayer.co.uk --- My Internet plumbing does not allow me to mail and post news together. Sorry. All opinions are my own and not those of Bayer plc. --- Join Infuse, the UK Informix User Group at http://www.infuse.org.uk/