Re: Database security
Posted in 1991
Path: emory!wupost!uunet!trac2000!peb From: peb@trac2000.ueci.com (Paul Begley {remote}) Newsgroups: comp.databases.informix Message-ID: <1085@trac2000.ueci.com> Date: 11 Oct 91 11:34:19 GMT References: <6170@jethro.Corp.Sun.COM> Organization: UE&C - Catalytic in Philadelphia, PA In article <6170@jethro.Corp.Sun.COM> myro@srfrogs.Corp.Sun.COM writes: >> Does anyone know a way to allow users to run a 4GL application that inserts >> and deletes from a database, but to disallow the users from altering the data >> by running isql? Here we run Informix-4GL version 4.00.UC1 for Sco Unix. >> >> Thanks for any help, >> Shane Booth >> shaneb@auzodt3.mel.cocam.oz.au > >Informix permissions are kept by the backend not the frontend, thus there is >no way to give access to a user under 4GL and not SQL. What _may_ work is to >turn on the setuid bit on for 4gl code. If the theory holds up, then all changes >made to the database will be made by one user, which may ruin other parts >of your database security. For example it will be next to impossible to track >who made what changes, and it will make any individual permissions useless. >Might be worth a try????? > >Mike Meyers We have this problem on our current project. There are many engineering applications which require insert/update/select permission on a production basis, but we also have a group of users who need to use ISQL for individual reporting requirements. Since this is engineering data we need to maintain revision and user data for each record based on the user name. Our solution was to write a front end in C which changes the effective UID to user 'informix' who has the proper permissions on the table. This application invokes the compiled 4GL application and passes the user name. scdinit peb elist Where scdinit is the C front end, peb is my user name and elist is our 4GL application. This allows us to track changes to records and restrict approval of records based on a user table we maintain in Informix. This works. We tried various other techniques posted here, but they would not allow unrestricted ISQL access while maintaining the integrity of our application tables. If anyone has any other techniques they are using in a production/development environment, please post.