Privileges on views
Posted in 2000
Topics: Server Administration, Security, Permissions & Auditing, Platform-Specific Issues, Versions, Editions & End-of-Life
With database connect and table select privileges as a regular user, I can create a view. However, I haven't been able to grant privileges to other users on this view until I'm granted DBA privilege. Why is this? Have I missed something? -- it doesn't make sense that I can create something but not give others access to that object. Also, what governs the privileges on a view? If I don't have select on another's view, or select is not granted to public for that view, I still have access to the view, so maybe grants on a view are superfluous?. How is this so? We're using IDS 7.31.UC-4 on Solaris 2.7/Intel (don't ask).
Red Valsen wrote in message <3A2D4B37.1A5C2607@yahoo.com>... >With database connect and table select privileges as a regular user, I >can create a view. However, I haven't been able to grant privileges to >other users on this view until I'm granted DBA privilege. Why is this? If you are not the owner of all the "objects" ie underlying tables of the view, then you cannot grant privileges on your view, because that would contradict the desired privileges set by the underlying owners. That's the principle, anyway. This is one reason it's a good idea to have a virtual user as the owner of database tables. Don't use root as a database account, just to admin the machine. Don't use informix as a database account, just to administer the engine. Make an "owner" account which is "root" for your database system and administer the database thru that. That's one suggestion, anyway...