Re: Database security
Posted in 1991
Path: emory!wupost!cs.utexas.edu!uunet!sequent!muncher.sequent.com!lugnut From: lugnut@sequent.com Newsgroups: comp.databases.informix Message-ID: <1991Oct9.170927.25294@sequent.com> Date: 9 Oct 91 17:09:27 GMT References: <503@rand.mel.cocam.oz.au> <13683@sbsvax.cs.uni-sb.de> Sender: news@sequent.com (News on Muncher) Organization: Sequent Computer Systems, Inc. In article <13683@sbsvax.cs.uni-sb.de> becker@ukh840.med-in.uni-sb.de writes: >shaneb@auzodt3.mel.cocam.oz.au (Shane Booth) writes: >> >> Does anyone know a way to allow users to run a 4GL application that inserts >> and deletes from a database, but to disallow the users from altering the data >> by running isql? Here we run Informix-4GL version 4.00.UC1 for Sco Unix. >> >> Thanks for any help, >> Shane Booth >> shaneb@auzodt3.mel.cocam.oz.au > >I asked this question to a representant of INFORMIX at the exposition of the >German Unix User Group. The answer was no. There is no Informix-tool to >decide which front-end is speaking with sqlexec/sqlturbo. Perhaps You can >use the setuid in Your 4gl-program for changing the owner. But this may be >difficult. Perhaps an rlogin as psuedo user "X" to invoke your 4gl program (the real user can be passed as an arg),this of course leads to other security issues on the host side, and requires you go carte blanche on the number of procs per user on a multiuser application, but is one approach to your problem thats relatively easy to do in *nix. Don "or you could create a view for the sql stuff and not tell-em the real table names" Bolton