Re: ODBC and Security
Posted in 1996
Irwin Goldstein wrote: > ... > Yours is a more secure approach, but is only possible if you have control > over the main application (i.e. it's maintained in-house). I don't know > if you can even do this kind of thing in Informix-4GL. (Is there a way > to "re-login" to the server using 4GL?) The CONNECT statement has a USER clause, enabling you to connect to the database server as a different user (supplying of course the password). Although Informix-4GL doesn't support this directly, you can create a simple esql/c function to do this. Note, you don't need to install esql/c to be able to do this. Such a function is included in the Power-4gl toolkit, which I include below. Note, you don't have to re-login. If your main function is contained in a module that does not contain a database statement at the top, then your program won't connect to the database until you do so explicitly, as with the connectdb function below. Save a second by connecting only once! > It would be nice if Informix (and other RDBMS vendors) would extend their > security mechanism to include such things as application id, remote system > name, etc. The hammer has struck the nail! ---------------------------------------------------------------------- John H. Frantz Power-4gl: Extending Informix-4gl frantz@centrum.is http://www.strengur.is/~frantz/pow4gl.html ---------------------------------------------------------------------- The following is a simple function in esql/c to connect to a database as a different user. The function can be called from an Informix-4gl function, as follows: call connectdb(dbase,uconn,uname,uauth) returning err_code. dbase is the name of the database. uconn is a connection name, which can be the real user name for instance. uname is the effective user name (i.e. "program"). uauth is the password of the effective user. #include <stdio.h> #include <sqlca.h> static void ferr(msg) char *msg; { fprintf(stderr,"%s",msg); exit(1); } int connectdb(nargs) int nargs; { $BEGIN DECLARE SECTION; char dbase[64]; char uconn[19]; char uname[19]; char uauth[19]; $END DECLARE SECTION; if (nargs != 4) ferr("connectdb: wrong number of arguments."); popstring(uauth, sizeof(uauth)); popstring(uname, sizeof(uname)); popstring(uconn, sizeof(uconn)); popstring(dbase, sizeof(dbase)); $connect to :dbase as :uconn user :uname using :uauth; retint(sqlca.sqlcode); return(1); }