Re: Security and the ODBC
Posted in 1997
I don't think the problem is primarily an ODBC Problem:
The only authentication against a INFORMIX-databse is by
username/password.
So any tool (e.g. Informix SQL-Editor via I-connect, dbaccess) that
lets you send SQL-statements to the database will cause these
problems.
So all real safe solutions have to be on the server side.
You could for example use some middleware as the only access method
via network to the database - but then you loose the chance to use
reporting tools, that use SQL.
Or there should be (my favorite) an additional authentication process
on the database to identify a program.
One way for that would be roles with passwords: the user as default
readonly status, only the application puts him into a special
read/write status.
But this is currently not possible with informix.
Tkelly@svhs.org (Tim Kelly) wrote:
>
>
>Ok, quick one. I have a Informix 7.x server running with a database. The
>users connect to it via Informix-CLI client from within Win95 using a
>complied program. The complied program handles the "business rules" of the
>database as far as insuring they have security etc. Simple example:
>
> One table they are allowed to insert rows and delete etc. But, the
>application checks a column called rsrc_id and doesn't allow them to delete
>or change a row if it isn't theirs (the rsrc_id is users name). It works
>fine. Remember this is just an example and I'm not wanting to know about
>Triggers, SPL etc.
>
> The issue is this: The CLI client is an ODBC driver. The user can use
>any ODBC application and point it to my Informix Server. Example being
>MS-Access. Now MS-Access (along with others) can just do what ever it
>wants to my data. In the above example the user is allowed to delete from
>the table and the application is ensuring the rsrc_id matches. So, is
>there a way to tell Informix to accept connections based on an application?
> Any ideas other then writing a billion triggers, SPL etc etc?
>
>
Harald Ums Tel : +49 (0)89-9507-5140
PRO 7 Televisions GmbH Fax : +49 (0)89-9507-5191
Bahnhofstra'e 28
D-80767 Unterf'hring e-mail: Harald.Ums@sevensys.de