Re: Security and the ODBC
Posted in 1997
Tim Kelly wrote: > > Ok, quick one. I have a Informix 7.x server running with a database. The > users connect to it via Informix-CLI client from within Win95 using a > complied program. The complied program handles the "business rules" of the > database as far as insuring they have security etc. Simple example: > > One table they are allowed to insert rows and delete etc. But, the > application checks a column called rsrc_id and doesn't allow them to delete > or change a row if it isn't theirs (the rsrc_id is users name). It works > fine. Remember this is just an example and I'm not wanting to know about > Triggers, SPL etc. > > The issue is this: The CLI client is an ODBC driver. The user can use > any ODBC application and point it to my Informix Server. Example being > MS-Access. Now MS-Access (along with others) can just do what ever it > wants to my data. In the above example the user is allowed to delete from > the table and the application is ensuring the rsrc_id matches. So, is > there a way to tell Informix to accept connections based on an application? > Any ideas other then writing a billion triggers, SPL etc etc? Try creating a view which includes all the columns of the base table and selects on the USER name and the user's name stored in the table. This view then contains only rows the user "owns". Grant only select to the base table and insert and delete to the view. This is textbook stuff. Peter -- Peter Lancashire Mail: Peter.Lancashire.PL1@bayer.co.uk Information Systems Specialist, Bayer plc Eastern Way, Bury St Edmunds, Suffolk, IP32 7AH, UK Tel: +44-1635-562258, Fax: +44-1635-562281 All opinions are my own and not those of Bayer plc.