Re: sessid or other connection info in SELECT
Posted in 2004
Richard Spitz <Richard.Spitz@med.uni-muenchen.de> wrote in message news:<gvg2605iuqfb6369gk4v94v2phuivnrkrk@4ax.com>... > mgage@talx.com (Mike Gage) wrote: > > >We have applications that access Informix (IDS 2000 Version 9.21 on > >Unix) via generic usernames. When a table is updated via one of these > >applications, I am looking for a way to tie, within Informix, the > >actual user with the change. > > Interesting question. We are presently considering a conversion from > our current individual-user-based approach (which means having to > administer access privileges on a per-user basis) to a generic-user- > approach, but are hesitating for the same reason. > > >If there is something similar to SELECT > >USER, but for some other parameter, like sessid, related to a > >connection, that would work > > How would sessid help you? You'd still have to find a way to > tie a session id to an individual user or process accessing > the database. If we could do something like SELECT sessid, we could populate a table linking the sessid and the actual user (as opposed to the role-based user), which could be used to track table changes. > > We are not so much looking for the capability to trace changes > in data to individual users, but we need to be able to identify > which user or process uses up which resources. Since we are in > a client-server environment, how could we link an Informix > session on the database server to a user or process on a > client machine? In a client-server environment there are some ways of making this work. One is to have groups of role-based user names, rather than one user name for each role, which are assigned from outside of Informix based upon priviledges at login. The key is to make sure that a user name is only used once. After login, the application updates a table linking the actual user to the role-based user name that is being used. Another option is to hide the actual database logon. The user logs into the application, but is not actually logging into Informix. The application determines what applications to offer the user, and logs the user in with his own id, but with a password that the user does not know (this could even be one password for everyone -- encrypted somewhere). > > >-- or if there is a way to pass data via > >the connection string that can be picked up in a SELECT statement, > >that would work, too. > > I am not aware of such extra parameters. > > Regards, Richard