Table privileges
Posted in 2011
Topics: Server Administration
I do a table info on a table in dbaccess, and get the following output:
public All All Yes Yes Yes Yes
public None None No No No No
What effect will this have on IDS ?
Dirk
________________________________
NOTE: This e-mail message is subject to the MTN Group disclaimer see
http://www.mtn.co.za/SUPPORT/LEGAL/Pages/EmailDisclaimer.aspx
On Tue, Jul 5, 2011 at 06:36, Dirk Cornel.... <moolma_dc@mtn.co.za> wrote:
> I do a table info on a table in dbaccess, and get the following output:
>
> public All All Yes Yes Yes Yes
>
> public None None No No No No
>
> What effect will this have on IDS ?
>
It will have no effect on IDS; it may confuse some DBAs, though.
I assume that there is some difference between the two rows - most likely
that there are different grantors, or maybe a difference in the references
privilege. Information is cumulative, so the chances are that everyone will
get access to the table for all purposes. It is a bit surprising to see all
negative permissions; normally that row would be deleted from the system.
There are limits to revoking everything from someone; the record is not
there and they only have permissions explicitly granted to them by other
people WITH GRANT OPTION on the table, or the permissions granted to PUBLIC.
--
Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h>
Guardian of DBD::Informix - v2011.0612 - http://dbi.perl.org
"Blessed are we who can laugh at ourselves, for we shall never cease to be
amused."
--005045015a6695cc7b04a75af97f
> -----Original Message-----
> From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of
> Jonathan Leffler
> Sent: Wednesday, 06 July 2011 01:38 AM
> To: ids@iiug.org
> Subject: Re: Table privileges [24227]
>
> On Tue, Jul 5, 2011 at 06:36, Dirk Cornel.... <moolma_dc@mtn.co.za>
> wrote:
>
> > I do a table info on a table in dbaccess, and get the following
> output:
> >
> > public All All Yes Yes Yes Yes
> >
> > public None None No No No No
> >
> > What effect will this have on IDS ?
> >
>
> It will have no effect on IDS; it may confuse some DBAs, though.
>
> I assume that there is some difference between the two rows - most
> likely
> that there are different grantors, or maybe a difference in the
> references
> privilege. Information is cumulative, so the chances are that everyone
> will
> get access to the table for all purposes. It is a bit surprising to see
> all
> negative permissions; normally that row would be deleted from the
> system.
> There are limits to revoking everything from someone; the record is not
> there and they only have permissions explicitly granted to them by
> other
> people WITH GRANT OPTION on the table, or the permissions granted to
> PUBLIC.
>
> --
> Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h>
> Guardian of DBD::Informix - v2011.0612 - http://dbi.perl.org
> "Blessed are we who can laugh at ourselves, for we shall never cease to
> be
> amused."
So in short, this line will take preference:
public All All Yes Yes Yes Yes
:-)
NOTE: This e-mail message is subject to the MTN Group disclaimer see
http://www.mtn.co.za/SUPPORT/LEGAL/Pages/EmailDisclaimer.aspx
On Wed, Jul 6, 2011 at 02:40, Dirk Cornel.... <moolma_dc@mtn.co.za> wrote: > > From: ... On Behalf Of Jonathan Leffler > [...long waffle...] > > So in short, this line will take preference: > > public All All Yes Yes Yes Yes > Yes Yes Yes Yes (all the time) -- Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h> Guardian of DBD::Informix - v2011.0612 - http://dbi.perl.org "Blessed are we who can laugh at ourselves, for we shall never cease to be amused." --0016e645ab025ea66704a768ef97