Re: Probs with WebExplode and Table Priviledges...
Posted in 1998
It sounds like you're not using table privileges at all. What happens
if, through the Web interface, the user tries to webexplode an arbitrary
page?
Anyway, the answer could be to use views on top of the webPages table
if you're using the APB schema or whatever table your application pages
are in if you're not. Then don't allow select directly on webPages.
Have your web.cnf (or whatever) Web driver configuration file specify
one of the views via the MItab parameter.
Seth
loeser@informatik.uni-kl.de (Henrik Loeser) writes:
>we have developed a simple web interface allowing for the execution
>of SQL statements entered by the user. The webdriver is configured
>to connect as a low-priviledged user (using MI_USER & MI_PASSWWORD),
>i.e., the user only has connect and select priviledges.
>By using the 'webexplode' function via the webdriver or invoking it
>directly in dbaccess, the user can circumvent all table priviledges.
>Is this a bug of the 'webexplode'-function or are there any workarounds?
--
--
Seth Grimes Alta Plana Internet & database design & development
grimes@altaplana.com http://altaplana.com 301-891-2581
grimes@access.digex.net http://www.access.digex.net/~grimes