Re: GRANT problems.
Posted in 1999
---- you wrote:
> >>>Update<<<
> When only granting select authority to the role, I cannot gain access to any
> tables through USER1. If I grant SELECT specifically to USER1 then it works
> fine. What am I doing wrong with the ROLE?
You are not using SET ROLE Dude. You can only wear one hat at a time. When you want to change to ROLE1, then say:
SET ROLE ROLE1
> Vincent Beggs <IfZenElse@yahoo.com> wrote in message
> news:uhex3.183$Hk7.5661@ord-read.news.verio.net...
> > I am just starting to work with Informix and am having a problem getting
> the
> > database to properly grant access to a set of tables. The database is
> > running on Windows NT 4.0 SP4, DS7.30 and is an ANSI Compliant database.
> >
> > I am using the following SQL:
> >
> > GRANT CONNECT TO USER1;> > CREATE ROLE ROLE1;
> > GRANT ROLE1 TO USER1;
> > GRANT SELECT ON OWNER.ADDRESS TO ROLE1 as OWNER;
> > GRANT SELECT ON OWNER.ORDER TO ROLE1 as OWNER;> >
> > After running these scripts and connecting to the database as USER1, I can
> > perform a select on the ADDRESS table but cannot select on the ORDER table
> > or any other tables that I grant access to. USER1 is a valid NT user.
> >
> > Am I performing the grant to the tables incorrectly or is there something
> > else wrong. Any help would be greatly appreciated.
You might want to make sure USER1 can't bypass your role with something like:
REVOKE ALL ON OWNER.ADDRESS FROM USER1
REVOKE ALL ON OWNER.ORDER FROM USER1
But an ANSI mode database should give no permissions by default.
Rock and Role Dude!
AB
----------------------------------------------------------------
Get your free email from AltaVista at http://altavista.iname.com