Re: Restricted DB access (was 'A quick question')
Posted in 1991
Some comments and questions related to the recent discussion of restricting database access in ISQL/I4GL environments.... When we first started developing a major application in 4GL, most of our users were very "turn-key." They wanted the custom app and e-mail, and that was pretty much it. So we just locked them into menus by exec'ing the main menu program from their .login/.profile. We provided a simple interface to e-mail from the menu program. If you go this route, you have to be careful about what system utilities you set up to be called from the menu. You have to worry about setting SHELL and whether a utility honors that variable correctly. Things like that. This approach worked well for most users, but was a major pain for other users who also had shell-level ID's. They had to log into the menu ID to use the app, then back into their shell ID to continue their other work. The irritation with this scheme has been reduced somewhat by short-cuts that are available to us since our environment is networked Sun systems. Various tricks are: having multiple sessions going on one Annex line, doing an rlogin back into your own system on the menu ID, and getting a windowed workstation. We are currently in the process of converting to a variation of the setuid method described by several list members. I have questions in several areas: 1) Has anyone had any problems running a setuid 4Gl app if you have already done an "su" or "su -" first? This is important in workstations. Does the USER function/keyword in SQL still work correctly? 2) Is anyone using this scheme under I-Net or I-Star? Problems/success? 3) How about under version 4.0? 4) On our system, the who and lpr/lpq/lprm commands use getlogin() to find out who you are, which returns the original login ID (not the setuid ID). Are there any other utilities that do this, and has this given anyone any problems? I'd appreciate any comments you'd care to make. It might save me a little time and/or paranoia. Thanks, Walt. -- Walt Hultgren Internet: walt@rmy.emory.edu Emory University, Atlanta, GA, USA BITNET: walt@EMORY Voice: +1 404 727 0648 UUCP: {...,rutgers,gatech}!emory!rmy!walt