Re: ODBC and Security
Posted in 1996
> > Some suggestions have been made as to granting and revoking access to > tables and columns. How do you deal with the situation where the 3rd party > application provides security at the value level? That is to say that a > particular user can only see rows in this table of the values meet certain > criteria (i.e. the salary is < $50000). Informix provides no means for > defining this type of security. It would also be nice if I-NET validated > the application that is connecting as well as the user. > Well, there are several ways you can deal with this problem. You can define views of your data that limit access. Of course, if your tables are still available to everyone then they could access the tables directly. You could install an Informix-Online Secure server. This server allows you define security levels to users and data so that a user without the proper security level could not see certain rows (or columns) in your tables even if they have direct access. But this is very complicated to setup. If you are not using the security features provided in your current (non-Secure) server, it is unlikely you will use the features provided by a Secure server.