Re: connect, resource and dba privileges
Posted in 1997
<HTML>
<P>Fuzzy wrote:
<BLOCKQUOTE TYPE=CITE>Hi people.
<P>There's a bit of a hole in my pdf versions of the documentation seem
<BR>to be a little "damaged". Under the "GRANT" statement, it says:
<P>"CONNECT, RESOURCE and DBA privileges are associated with the
<BR>following keywords:"
<P>and then doesn't list anything. I was expecting to see a list
of what
<BR>each level gave in terms of granted privileges. Could anyone
out
<BR>there provide me with a list of these, or point me to an on-line
<BR>source that has them?
<P>Thanks
<BR>Fuzzy
<BR>:-)</BLOCKQUOTE>
It's documented in the "Informix Guide to SQL - Syntax". It says:
<P>CONNECT gives you the ability to query and modify
data. You can modify the the database schema if you own the object you
want to modify. Any user with the connect privilege can perform the following
functions:
<UL>
<LI>
Execute SELECT, INSERT, UPDATE and DELETE statements, provided the user
has the necessary table privileges</LI>
<LI>
Create views, provided the user has the select privilege on the underlying
tables</LI>
<LI>
create synonyms</LI>
<LI>
create temporary tables and create indexes on the temprary tables</LI>
<LI>
alter or drop a table or an index, provided the user owns the table or
index (or has alter, index or references privileges on the table)</LI>
<LI>
grant priivileges on a table or view, provided the user owns the table
(or has been given privileges on the table with the WITH GRANT OPTION keyword)</LI>
</UL>
RESOURCE gives you the ability to extend the structure
of the database. In addition to the capabilities of the Connect privilege,
the holder of the Resource privilege can perform the following functions:
<UL>
<LI>
Create new tables</LI>
<LI>
Create new indexes</LI>
<LI>
create new procedures</LI>
</UL>
DBA has all capabilities of the resource privilege as
well as the ability to perform the following functions:
<UL>
<LI>
grant any database-level privilege, including the DBA privilege, to anotheruser</LI>
<LI>
use the NEXT SIZE keyword to alter extent sizes in the system catalog</LI>
<LI>
Insert, delete or update rows of any system catalog table except <B>systables</B></LI>
<LI>
drop any object, regardless of its owner</LI>
<LI>
create tables, views and indexes and specify another user as owner of the
objects</LI>
<LI>
execute the DROP DATABASE statement</LI>
<LI>
execute the DROP DISTRIBUTIONS option of the UPDATE STATISTICS statement.</LI>
<LI>
execute the START DATABASE and ROLLFORWARD DATABASE statements</LI>
</UL>
User <B>informix</B> has the privilige required to alter tables in the
system catalog, including the <B>systables</B> table.
<BR>
<P>Helmut Leininger
<BR>UNIX Support
<BR>Bull AG
<BR>Email: Helmut.Leininger@bull.net</HTML>