Re: ODBC and Security
Posted in 1996
marco greco wrote: > ... > John, > I agree with most of what you have written in this thread (in particular, > when you say that 4gl is still adequate for most users needs). I cannot but > note however that your solution does not address the problem of granting > different rights to different users. > ... My solution basically splits security into two segments, read access and write access. Read access to data is not as critical and is easier to setup and maintain in the database using views and such. Thus the users get appropriate read access to data using their own id's, and they can use other clients like ODBC to make fancy reports and on-the-fly queries. Write access to data is taken out of the database (because it's too hard to solve using SQL programming) and put into the maintenance application (i.e. I4gl). Different rights to different users is controlled in that application, probably by setting up access tables in the database. I've done this by setting up 3 tables: access_sets, set_tables and set_users. An access_sets row defines a basic unit of security. Tables are connected to access_sets via set_tables, and users are given read or write access to access_sets via set_users. A simple set of functions maintain these tables (of course, using Power-4gl pick-lists). I can even use these tables to produce appropriate GRANT SELECT statements, so that maintaining security is in one convenient place. So, although the maintenance application connects to the database as a single user that has full write access to the database, it takes care of security on the individual user level. ---------------------------------------------------------------------- John H. Frantz Power-4gl: Extending Informix-4gl frantz@centrum.is http://www.strengur.is/~frantz/pow4gl.html