Re: [Q] UPDATE permissions
Posted in 1998
Sergey Oleshko wrote:
> is having Update permissions not enough to modify data ?
>
> I found that users having granted update permission via role
> cannot modify table data unless update statement is issued with
> no where clause.
> The error number is ` -272 No SELECT permissions' (why select ?).
> Note such bevahior disagrees with Guide to SQL - Tutorial, p.10-9,
> which says `...grant Update privilege to make users to be able update
> rows... . However, you might grant Select privilege to only few users.'
>
> So, the questions are:
> 1. Is Select privilege required to make users to be able to modify any row?
> 2. Is the bevavior server-specific? Tested was IDS 7.22 for SCO UNIX,
> non-ANSI mode.
I have seen this before. There was some debate as to whether this actually was
a bug or not. Let's say my database has payroll information, and I do not have
permission to select data -- salary, for instance. If I could still do your
update, then I would be able to figure out what someone's salary was by doing
something like:
UPDATE personnel SET lname = lname WHERE lname = 'Akins' AND salary > 100000If it says "0 rows updated." then I know that Akins makes < 100000.
So I suspect that it is not a bug. You probably do need to have select
permission on a column in order to use it in a WHERE clause.
I don't see any conflict with the manual reference you cited; of course, that
may be because there isn't enough of the reference to figure out what they were
talking about.
June
--
june_t@hotmail.com
Lost in the wilds of Palo Alto, living on Peanut M&M's