Another user is not connected
Posted in 1999
Topics: Security, Permissions & Auditing
Hi All, Anybody can help me? Assume, I'm user 'userA1', and I have created database 'db01' with many tables. In the system (not in the database), I have a user 'userA2' also. My problem is next. After I grant connect to db01 to user 'userA2' and grant select on some tables in db01 to userA2, userA2 can connect to db01, but when it execute something like "select * from sometable" (sometable a table in db01 and userA2 have a select privileges), it get a message "ERROR: Table userA2.sometable not found". What I'm missing and where is my mistake? P.S. Before I grant select to user userA2, I revoke all privileges from user public (REVOKE ALL FROM PUBLIC). Thank you very much, Ruslan
Ruslan Satlykov wrote: > Anybody can help me? Assume, I'm user 'userA1', and I have created > database 'db01' with many tables. Is it a MODE ANSI database? > In the system (not in the database), I have a user 'userA2' also. > My problem is next. After I grant connect to db01 to user 'userA2' > and grant select on some tables in db01 to userA2, userA2 can > connect to db01, but when it execute something like > "select * from sometable" (sometable a table in db01 and userA2 > have a select privileges), it get a message > "ERROR: Table userA2.sometable not found". > What I'm missing and where is my mistake? > > P.S. Before I grant select to user userA2, I revoke all privileges > from user public (REVOKE ALL FROM PUBLIC). Since the database is interpreting SomeTable as userA2.sometable, I'm virtually certain that the database is a MODE ANSI database and that therefore all users will always have to prefix the correct owner name to any table reference where they do not own the table. For general purpose code that will be used by more than one user, that means *all* table references must be qualified by the correct owner name. Further, it means you need to keep careful track of who owns which tables. The simplest scheme is to have a specially created DBA user own all the tables; that way, you can always use the same owner name everywhere. You can impose more complex schemes with different parts of the database owned by different users if you wish. The key thing is that every table has a permanently identified owner, and all programs are written to specify that owner every time the table is referenced. -- Jonathan Leffler (jleffler@informix.com, jleffler@earthlink.net) Guardian of DBD::Informix v0.60 -- see http://www.perl.com/CPAN #include <disclaimer.h>