Re: Post 4.1 Questions
Posted in 1995
Stan,
> Stan Wolfe asked:
> 1) Is this syntax valid:
> GRANT priv (column1), priv (column2) ON owner.table TO user;> for example:
> GRANT UPDATE (customer_name), INSERT (customer_address) ON customers TO stan;> This is valid in Oracle but I don't think it's valid ANSI SQL.
The problem with this statement is you cannot insert a row into one column, so
insert privileges only apply to the whole record and not columns. To insert a
row you will need insert privileges on all columns in the row. I don't know
what the ANSI SQL standard is on this one for sure. One of Date's books on
the SQL Standard makes refernece to granting insert(column_name) privileges.
I just tried the following in dbaccess.
You can do:
GRANT UPDATE (customer_name), INSERT ON customers TO stan;
and:
GRANT UPDATE (customer_name), SELECT (customer_address) ON customers TO stan;
However, this statement returns a syntax error.
GRANT UPDATE (customer_name), INSERT (customer_address) ON customers TO stan;
Select and Update are the two main column level provileges.
> 2) Are there _roles_ in any recent version of Informix, where a role is:
> create role sales_rep identified by password;
> grant select on sales_history to sales_rep;
> grant sales_rep to stan;>
Yes, roles are in Informix 7.1UD1, I am working on a project to add
them to our security package. The systax is a little different from the
above.
Regards - Lester
#############################################################################
# Lester Knutsen lester@access.digex.net #
# Advanced DataTools Corporation Voice: 703-256-0267 #
# Grant group privileges for Informix databases with DB Privileges #
# Visit our Web page: http://www.access.digex.net/~lester #
#############################################################################