Re: Check current permissions?
Posted in 2004
Topics: Connectivity: ODBC / JDBC / .NET, Server Administration, Security, Permissions & Auditing, Versions, Editions & End-of-Life
Thanks Jonathan, I do know the user name, since that's used to establish the connection in the first place. I'm not familiar with the "role" though. FYI - We're using IDS 7.31. -- William Fields MCSD - Microsoft Visual FoxPro MCP - Win2k Pro US Bankruptcy Court Phoenix, AZ "Don't look back - we're not going that way." - Terry Hunefeld "Jonathan Leffler" <jleffler@earthlink.net> wrote in message news:jDC8c.264$lt2.211@newsread1.news.pas.earthlink.net... > William Fields wrote: > > I have an open ODBC connection to our Informix server and would like to > > determine what permissions the connection has on different tables. I've > > checked out DBINFO, but don't see anything that would help me. I've also > > looked into the INFO command, but I don't think I can issue an SQL statement > > that includes that command the way I can with DBINFO. > > You're going to need to know the current user (session authorization) > and current role (if any). > > For each table, you take the union of the privileges for the current > user, current role and PUBLIC. You poke in systabauth and syscolauth > sometimes. You also poke at sysprocauth. And you review sysusers > (heaven help you if it contains an entry asserting that PUBLIC is a DBA). > > There isn't a single statement that can do that - though DB-Access's > INFO PRIVILEGES statement might help a bit. > > -- > Jonathan Leffler #include <disclaimer.h> > Email: jleffler@earthlink.net, jleffler@us.ibm.com > Guardian of DBD::Informix v2003.04 -- http://dbi.perl.org/ >
William Fields wrote: > Thanks Jonathan, I do know the user name, since that's used to establish the > connection in the first place. I'm not familiar with the "role" though. The RTF(abulous)M for CREATE ROLE and SET ROLE. However, the chances are you are not using them. OK - so you've got the info you need - go to it! The system catalog awaits you. (You might, conceivably, need to look in the Informix Guide to SQL: Reference manual for information about the coding of permissions in systabauth.) > FYI - We're using IDS 7.31. Fine. Start planning to upgrade to 9.40. And what are the letters after the 7.31; if they aren't UD7 or FD7 or TD7, you should be aiming to upgrade to that - even before you upgrade to 9.40. >> "Jonathan Leffler" <jleffler@earthlink.net> wrote: >>> William Fields wrote: >>>>> I have an open ODBC connection to our Informix server and >>>>> would like to determine what permissions the connection has >>>>> on different tables. I've checked out DBINFO, but don't see >>>>> anything that would help me. I've also looked into the INFO >>>>> command, but I don't think I can issue an SQL statement >>>>> that includes that command the way I can with DBINFO. >>> >>> You're going to need to know the current user (session authorization) >>> and current role (if any). >>> >>> For each table, you take the union of the privileges for the current >>> user, current role and PUBLIC. You poke in systabauth and syscolauth >>> sometimes. You also poke at sysprocauth. And you review sysusers >>> (heaven help you if it contains an entry asserting that PUBLIC is a DBA). >>> >>> There isn't a single statement that can do that - though DB-Access's >>> INFO PRIVILEGES statement might help a bit. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2003.04 -- http://dbi.perl.org/