Re: Updates...
Posted in 1994
> users can make requests. I designed a screen that controls usage based
> on user's login. I've also created a logfile to track activity which
> datestamps additions and modifications. Everything works fine! Except,
> I'm dealing with 2 tables (reqhead,reqitems), all users have update
> permissions and the screen controls what the user is allow to enter/
> update.
>
> I keep thinking that a user, (that knew how) could create a form using
> sformbld and update the data to whatever, bypassing the screen controls.
>
> Bob
Bob,
You don't mention what software you are using but an option exists on
5.0 and above engines using esql/c or 4gl for the front end. If you
remove all update/insert/delete priviliges from the tables and you
call dba priviliged stored procedures to do all the updating work,
from your programmed front end instead of using direct insert, update,
delete statements.
This will result in no one having update access to the tables except
through the stored procedures. Users, that is very knowledgable
users, would still be able to call the stored procedure directly using
dbaccess. But the code in the stored procedure can be written to
guarantee integrity, test users permission levels and any other
business rules you may have. This means that they can avoid your
front end but they cannot bypass your checks.
Cheers - Jim
My opinions are my own. They may vary with time but they remain MINE!
----------------------------------------------------------------------
Name: Jim Gordon Company: DHL Systems Inc, Burlingame, CA, USA
----------------------------------------------------------------------