Re: Security and the ODBC
Posted in 1997
Mike Segel <Postmaster@127.0.0.1> wrote in article <34117999.6E7E@127.0.0.1>... > Tim Kelly wrote: > > > MS-Access. Now MS-Access (along with others) can just do what ever it > > wants to my data. In the above example the user is allowed to delete from > > the table and the application is ensuring the rsrc_id matches. So, is > > there a way to tell Informix to accept connections based on an application? > > Any ideas other then writing a billion triggers, SPL etc etc? > > First idea: > Use the permissions of the database to control user's permissions. > Second, and a different tact. > Create a *user* per application. Then control to the database > based on the application id. Of course, then you need to have your > application authenticate the actual user id. > > At first blush, either one will work. Another option is to go with the OpenLink Multi-Tier ODBC driver which includes a request broker on the server which allows you to limit sessions to read only status based upon various combinations of user-ID, host name/IP address, client application, client OS, etc. You can (if desired) then disable "native" Informix ODBC access to the server by not configuring a TCP/IP connection on the Informix server. (In case a really clever user obtains and installs the "native" ODBC driver.) The network communication in OpenLink is between the client and the request broker. The request broker can use a shared memory connection to the database. I have setup and used a similar configuration with OpenLink and MS-Access at several clients. This allowed users to use MS-Access as a report writer while protecting the database from updates through Access (or any other PC based tool). -- Irwin Goldstein Objective Software Systems, Inc. http://www.objectsoft.com