Re: restrict access for an user doesn't work, again
Posted in 1999
On Tue, 15 Jun 1999, georges Chaleunsinh wrote:
> hi,
> I fixed partially my problem. before granting select to the user, I have to
> revoke all on this table frompublic. But it doesn't work when the table
> belongs to another user although I use Informix id.
>
> I'm using IUS 9.14.UC3 on solaris 2.5.1
>
> Suppose we have three ids informix, visitor who can just select table and
> the table's owner O.
> O create a table with this request: create table test (foo interger);
> Oddly Informix can't change the privilege on the table test
>
> visitor have the connect privilege.
> O have the resource privilege.
>
> Using this request by Informix doesn't work:
> REVOKE ALL ON test FROM public;
> GRANT SELECT ON test TO visitor;>
> I need to be O so that request works.
> Is it normal?
> thanks for your help.
>
> georges
>
>
>
Generally speaking, the user that has been granted the *DBA*
privilege on the database should own all of the tables. Otherwise you get
the problems that you are having. That is to say, one user cannot change
a table that another user *owns*. To correct your problem, decide which
user is going to have dba privilege on your database. Then, AS THAT USER,
unload, drop and recreate all tables that are owned by another user.
When you are first getting started, only the dba user should own the
tables in a database. You can get more exotic later.
There is another solution where you grant dba database privileges to more
than one user, but that has its own set of complications which I don't
have time to go into here. Besides, you can play with the concept
of multiple dba users on your own.
====================================================================
Harold Luse Phone: (970) 491-4120
Veterinary Teaching Hospital Fax: (970) 491-4123
Colorado State University Pager: (970) 229-8173
Fort Collins, Colorado USA E-mail: hluse@vth.colostate.edu
====================================================================