Re: Security and the ODBC
Posted in 1997
Tim Kelly wrote: > MS-Access. Now MS-Access (along with others) can just do what ever it > wants to my data. In the above example the user is allowed to delete from > the table and the application is ensuring the rsrc_id matches. So, is > there a way to tell Informix to accept connections based on an application? > Any ideas other then writing a billion triggers, SPL etc etc? First idea: Use the permissions of the database to control user's permissions. Second, and a different tact. Create a *user* per application. Then control to the database based on the application id. Of course, then you need to have your application authenticate the actual user id. At first blush, either one will work. -- #include <std_disclaimer.h> /* Mike Segel (MS385) */ #include <No_Spam.h> #ifdef OFFENDED_BY_CONTENT The author takes no responsibility for this post. Any resemblence to a coherent rational thought is purely coincidence. -The Management. #endif ***************************** Due to AGIS's Refusal to Act Responsibly We are blocking all of their domains at the packet level. This block will exist until AGIS modifies their policies to conform to existing RFCs and net community standards. We encourage all ISPs and domain holders to do the same. *****************************