Re: default privs for public
Posted in 1996
Patrick,
I'm not entirely clear what your problem is.
The default privileges seem to include INDEX privileges (the 'x'), but
otherwise the comments you quote are correct according to the data you
supply. The 'su-idx--' pattern has been the case since I can remember
(well, OK, the last dash is for REFERENCES privileges, and only came along
with 5.00, but that's nit-picking), so I'd suggest that there is a minor
problem in the manual (it exists in the 7.1 Informix Guide to SQL: Syntax
too).
Note that if you were using a MODE ANSI database, PUBLIC would not have
those privileges. And by granting the privileges to PUBLIC, any user who
can connect to the database will be able to do as PUBLIC can.
In fact, as far as I can tell, you cannot make the privileges for a user
UserA more restrictive than the privileges for PUBLIC. I just did some
testing, creating a database and table as myself, and then doing 'su usera'
and inserting data into table A:
-- As 'johnl'...
1: create database junk;
2: create table a (b integer not null);
3: grant select on a to usera;
4: select * from sysusers;
5: grant connect to usera;
6: select * from systabauth where tabid >= 100;
johnl|public|100|su-idx--
johnl|usera|100|s-------
-- As 'usera'
7: insert into a values(1);
This was testing with 6.00.UE1 SE on Solaris 2.4, but I don't think the
behaviour has changed in a long time...
Yours,
Jonathan Leffler (johnl@informix.com) #include <disclaimer.h>
>From: Patrick Soehl <102121.3564@CompuServe.COM>
>Date: 1 Mar 1996 00:05:13 GMT
>X-Informix-List-Id: <news.21652>
>
>According to the "Guide to SQL Reference, DEC 1991", when
>creating a table, "all users who have been granted Connect
>privilege to a database have all access privileges (except Alter,
>Index and References) to the new table." Doesn't seem to be
>true. I create a db, create a boatload of tables. Have NOT
>granted public any rights (explicitly). Yet the following:
>
> select * from systabauth;>[snip a few rows]
>
>informix public 23 s-------
>msddba public 100 su-idx--
>msddba public 101 su-idx--
>msddba public 102 su-idx--
>msddba public 103 su-idx--
>[snip some more]
>
>select * from sysusers;>
>username usertype priority password
>
>msddba D 9
>
>1 row(s) retrieved. We're using OnLine 5.0.5.