Re: How to limit database access with dbaccess and/or isql
Posted in 1995
In article <DFBLtK.BI@txnews.amd.com>,
Ben Van Truong <ben.truong@amd.com> wrote:
>To ensure no damage can be made to database, I
>would like to restrict some SQL verbs such as INSERT, DELETE, DROP, etc. while
>they're using the dbaccess and isql tools.
One way is to run your menu-controlled application setuid to a different
user-ID for each user allowed to use it. A variation of this approach
is to run it setuid to the same user-ID for all such users. This is not
my preference of the two methods, but it's easier to manage if your
application allows it.
You can then grant the privileges needed by the application to the setuid
ID(s), and more restrictive privileges (e. g., only SELECT) to the ID's that
people use to log into the system.
There is a paper with some example code that explains a way of implementing
this scheme in the file ftp://mathcs.emory.edu/pub/informix/pub/appstart.
Good luck,
Walt.
--
Walt Hultgren Internet: walt@rmy.emory.edu (IP 128.140.8.1)
Emory University UUCP: {...,gatech,rutgers,uunet}!emory!rmy!walt
954 Gatewood Road, NE BITNET: walt@EMORY
Atlanta, GA 30329 USA Voice: +1 404 727 0648