Re: Granting privileges to a group of users
Posted in 1992
chris@green.att.com writes:
> Using Informix-SE, I know it is possible to grant table and
> database privileges to a user or a comma separated list of users. I
> would like to know if it is possible to grant privileges to a group
> of users ala UNIX's /etc/group.
>
> Suppose group "clerk" contains "mary, sue, joe, fred" and group
> "manager" contains "larry, curly, moe." It sure would make administration
> easy if you could say:
>
> grant select on employee to clerk;
> grant insert, delete, update on employee to manager;>
> When more people were added to a group, you wouldn't have to remember to
> grant privileges.
There's a hacked-up shell script at the bottom which should do most of
what you want (sorry, I got bored towards the end :-)
In any case, you can hack it some more if you need to. If it does
strange things, add "set -x" somewhere near the top for debugging info.
Caveat: I didn't check much for errors ...
Thanks - all - for the good stuff posted recently, btw. Much appreciated
in this neck of the woods. Thanks to DAS for the 4gltags copy, too.
Cheers - Tony.
__________________________________________________________________________
Tony Heskett th@bnr.co.uk Voice: (+44) 279 429531 x 2637
BNR, London Road, Harlow, Essex, CM17 9NA Fax: (+44) 279 454187
__________________________________________________________________________
:
# Script to read DB, unix group, permissions to alter and table name.
# Converted to sql and executed.
#
# Tony Heskett Wed Mar 18 19:08:23 GMT 1992
echo -n "enter database to modify: "
DB=`line`
if [ -z "${DB}" ]
then
echo "Sorry, no DB !"
exit 1
fi
echo -n "enter group to modify: "
GRP=`line`
# pick any one from two ...
USERS=`awk -F: '{ if ($1 == "'${GRP}'") print $NF}' /etc/group`
# USERS=`ypmatch ${GRP} group 2>/dev/null | sed 's/.*://g'`
if [ -z "${USERS}" ]
then
echo "Sorry, no-one in that group !" 1>&2
exit 1
fi
PERMS=""
while true
do
echo -n "enter permission to alter (a, i, d, s, u, q=quit prompt) : "
PRIV=`line`
case ${PRIV} in
a|A)
PERMS="all"
echo all
break
;;
i|I)
if [ -z "${PERMS}" ]
then
PERMS=insert
else
PERMS="${PERMS}, insert"
fi
echo insert
;;
d|D)
if [ -z "${PERMS}" ]
then
PERMS=delete
else
PERMS="${PERMS}, delete"
fi
echo delete
;;
s|S)
if [ -z "${PERMS}" ]
then
PERMS=select
else
PERMS="${PERMS}, select"
fi
echo select
;;
u|U)
if [ -z "${PERMS}" ]
then
PERMS=update
else
PERMS="${PERMS}, update"
fi
echo update
;;
q|Q)
break
;;
*)
echo unknown
;;
esac
done
echo -n "table to mod perms on: "
TABLE=`line`
if [ -z "${TABLE}" ]
then
echo "Sorry, no table !"
exit 1;
fi
while true
do
echo -n "grant or revoke (g,r) ? "
TYPE=`line`
case ${TYPE} in
g|G)
TYPE=grant
break
;;
r|R)
TYPE=revoke
break
;;
*)
;;
esac
done
echo "database ${DB}; ${TYPE} ${PERMS} on ${TABLE} to ${USERS} ; " |
isql -