revoke select, doesnt work
Posted in 2007
Topics: SQL Development & Query Writing, Security, Permissions & Auditing
I created a user named 'kevin' through 'informix' user and granted him connect permission on the database. Next I revoked 'select' permission on table 'temp1' from user 'kevin'. The statement is "revoke select on temp1 from kevin" Command executes successfully but after it when connected thru 'kevin', can still view the data in temp1 using select statement. How can i restrict the access of a user on any table. Please help...
Naeem wrote:
> I created a user named 'kevin' through 'informix' user and granted him
> connect permission on the database. Next I revoked 'select' permission
> on table 'temp1' from user 'kevin'. The statement is
> "revoke select on temp1 from kevin"
> Command executes successfully but after it when connected thru
> 'kevin', can still view the data in temp1 using select statement.
> How can i restrict the access of a user on any table. Please help...
>
You should check the permissions on that table. You can do it using dbaccess or:
dbschema -d <your_database> -t <your_table> -p all
If you have public permissions on the table you'll still be able to access it
with "kevin" even if he doesn't have explicit grants on it for him.
Regards.
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
Check the contents of systabauth.
select grantor, grantee, tabname, tabauth
from systables a, systabauth b
where a.tabid=b.tabid
and (b.grantee='kevin' or b.grantee='public')
and a.tabname='temp1'
and tabauth[1,1]='s';
This will tell you how kevin has permission to select from the table -
probably because you didn't also revoke select from public.
The second possibility is that some other user id (grantor) granted select
to kevin - this will also show you that. check syntax for revoke, you can
revoke AS user.
j.
-----Original Message-----
From: informix-list-bounces@iiug.org
[mailto:informix-list-bounces@iiug.org]On Behalf Of Naeem
Sent: Friday, June 15, 2007 7:19 AM
To: informix-list@iiug.org
Subject: revoke select, doesnt work
I created a user named 'kevin' through 'informix' user and granted him
connect permission on the database. Next I revoked 'select' permission
on table 'temp1' from user 'kevin'. The statement is
"revoke select on temp1 from kevin"
Command executes successfully but after it when connected thru
'kevin', can still view the data in temp1 using select statement.
How can i restrict the access of a user on any table. Please help...
_______________________________________________
Informix-list mailing list
Informix-list@iiug.org
http://www.iiug.org/mailman/listinfo/informix-list
Naeem wrote: > I created a user named 'kevin' through 'informix' user and granted him > connect permission on the database. Next I revoked 'select' permission > on table 'temp1' from user 'kevin'. The statement is > "revoke select on temp1 from kevin" > Command executes successfully but after it when connected thru > 'kevin', can still view the data in temp1 using select statement. > How can i restrict the access of a user on any table. Please help... that's because there's an implicit grant select on temp1 to public.... you have got to revoke select from public and grant it to whoever should be able to access the table -- Ciao, Marco ______________________________________________________________________________ Marco Greco /UK /IBM Standard disclaimers apply! Structured Query Scripting Language http://www.4glworks.com/sqsl.htm 4glworks http://www.4glworks.com Informix on Linux http://www.4glworks.com/ifmxlinux.htm