Re: Batch deletion of user privileges?
Posted in 2003
Richard Spitz wrote: > Hi Informixers, > > we are presently removing some dozens of user accounts from our > Unix system (regular "housekeeping"). Since most of these accounts > have access privileges in one or more of our Informix databases, I > am looking for an easy way to remove these privileges. > > Rather than having to issue hundreds of "revoke all on <tablename> > from <user>" and "revoke connect from <user>", is there a more > effective way to do this? > > I'm thinking of "delete from systabauth where grantee in ("user1", > "user2", ...) and "delete from sysusers where username in ..."). > Is this safe and does it achieve the desired effect? > > I don't expect this to be officially supported, but that's fine > with me as long as it does what it's supposed to do, without > any undesirable side effects. I have written scripts in the past that hack these tables directly. Couldn't tell you which version. Couldn't say if these tables still allow that type of access today. What you could do is load the user names into a table, then write an SQL query that generates the REVOKE commands for you. You can even get it to run them if you use the OUTPUT command. This might be a safer, and supported way of tackling the problem. Cheers, -- Mark. +----------------------------------------------------------+-----------+ | Mark D. Stock mailto:mdstock@MydasSolutions.com |//////// /| | Mydas Solutions Ltd http://MydasSolutions.com |///// / //| | +-----------------------------------+//// / ///| | |We value your comments, which have |/// / ////| | |been recorded and automatically |// / /////| | |emailed back to us for our records.|/ ////////| +----------------------+-----------------------------------+-----------+ sending to informix-list