Re: Run 4GL Program without Database Permissions?
Posted in 1996
Richard Spitz wrote: > > Steven Hauser (hause011@maroon.tc.umn.edu) wrote: > : How about a stored procedure owned by a user that has the rights to the > : 2nd database, the procedure can be called by any user on the first database > : and executes with the rights of the procedure owner. > > Yes, but to execute the procedure, a user still needs CONNECT privilege > for the 2nd database. I want to avoid having to grant (and administrate) > any privileges for the 2nd database to the users of the 1st. > > Regards, Richard > -- > +----------------------------+-------------------------------------------+ > | Dr. Richard Spitz | INTERNET: spitz@ana.med.uni-muenchen.de | > | EDV-Gruppe Anaesthesie | Tel : +49-89-7095-3413 | > | Klinikum Grosshadern | FAX : +49-89-7095-8886 | > | 81366 Munich, Germany | | > +----------------------------+-------------------------------------------+ I would have thought that administering the extra privileges would have been the least of your problems. Otherwise you have to worry about the security of setuid root programs and the loss of any possibility of audit trails. Ian