system permissions
Posted in 2004
Topics: Triggers, Constraints & Referential Integrity
On Tue, 07 Sep 2004 14:57:55 -0400, Matt wrote:
The system command is being run by the engine which, in 9.xx, runs as user
informix. In order to run the system command string for each user as that
user, the engine must know the user's password. If you users are connecting
without a password using trusted host status, then the engine will not have
the password to be able to su to the user's id to run the string. Thus the
-668 error.
Art S. Kagel
> I'm trying to create a trigger on a record for when a certain field is
> updated, using a procedure. The procedure works fine when I, having
> administrative powers, run it, but when any of the users try it, it gets an
> error (-668). It appears that any system command causes the error. Here is
> the code. If anyone has any ideas, please let me know. Thanks.
>
> procedure grpeml
> privilege owner
> description "Sends e-mail to registrar when a student's group number
> changes"
> inputs in_id int "student id"
> new_grp char(4) "new group"
> old_grp char(4) "old group"
> notes "Runs from trigger in prog_enr_rec when assigned"
>
> begin procedure
> DEFINE mailcall char(100);
> DEFINE stuname char(30);
>
> SELECT fullname
> FROM id_rec
> WHERE id_rec.id = in_id
> INTO temp tmp_c;>
> SELECT fullname
> INTO stuname
> FROM tmp_c;>
> DROP table tmp_c;>
> IF (stuname is null) THEN let stuname = " "; END IF
>
> SYSTEM '/usr/bin/echo "This notice is to inform you that ('||
> in_id ||') '|| stuname ||'" > /tmp/testmail';
> SYSTEM '/usr/bin/echo "has been changed from group '|| old_grp
> ||' to '|| new_grp2 ||'" >> /tmp/testmail';
>
> LET mailcall = '/usr/bin/mailx -s "Group Change Notification"
> psmith@ksu.edu < /tmp/testmail';
>
> SYSTEM mailcall;
>
> SYSTEM '/bin/rm /tmp/testmail';
>
> end procedure
>
> grant
> execute to (group admissions, group carsprog, group registrar)
I'm trying to create a trigger on a record for when a certain field is
updated, using a procedure. The procedure works fine when I, having
administrative powers, run it, but when any of the users try it, it
gets an error (-668). It appears that any system command causes the
error. Here is the code. If anyone has any ideas, please let me know.
Thanks.
procedure grpeml
privilege owner
description "Sends e-mail to registrar when a student's group
number changes"
inputs in_id int "student id"
new_grp char(4) "new group"
old_grp char(4) "old group"
notes "Runs from trigger in prog_enr_rec when assigned"
begin procedure
DEFINE mailcall char(100);
DEFINE stuname char(30);
SELECT fullname
FROM id_rec
WHERE id_rec.id = in_id
INTO temp tmp_c;
SELECT fullname
INTO stuname
FROM tmp_c;
DROP table tmp_c;
IF (stuname is null) THEN let stuname = " ";
END IF
SYSTEM '/usr/bin/echo "This notice is to inform you that ('||
in_id ||') '|| stuname ||'" > /tmp/testmail';
SYSTEM '/usr/bin/echo "has been changed from group '|| old_grp
||' to '|| new_grp2 ||'" >> /tmp/testmail';
LET mailcall = '/usr/bin/mailx -s "Group Change Notification"
psmith@ksu.edu < /tmp/testmail';
SYSTEM mailcall;
SYSTEM '/bin/rm /tmp/testmail';
end procedure
grant
execute to (group admissions, group carsprog, group registrar)