Re: Informix security questions
Posted in 1997
At 09:59 AM 11/3/97 -0500, you wrote:
>I have two basic security questions about Informix:
>
>1. Is it true that if a user has execute permission on a stored proc,
>then the stored proc will be allowed to perform any table reads or
>updates (regardless of the original user's security profile). In other
>words, stored procedures are not "held back" by the initiating users'
>security level.
This is an advantage. A properly written stored procedure allows the user
to execute with the SPs authors permissions - even though they have none
themselves. This means you can lock them out from all of the tables and
force them to use the SP to manipulate them.
>
>2. Does Informix support specifying security down to the column level?
Yes. It's stored in syscolauth.
GRANT permission (column_list) ON table TO user_list
cheers
j.