Re: Create Roles
Posted in 1997
On Fri, 24 Oct 1997, Harold Luse wrote:
> Does anybody know the syntax for the create role statement? I have looked
> through all of our informix books and I can't find any references to the
> exact syntax to use.
CREATE ROLE rolename;
In I4GL, you'll have to prepare it. You then grant privileges to the role,
and the role to users:
GRANT SELECT ON SomeTable TO rolename; FRANT rolename TO someuser; -- or another rolename
> Also any comments on using roles to limit access to the databse would be
> appreciated.
I would expect to use roles to allow (extend) access to the database,
rather than limit it. The default (PUBLIC) permissions should be the most
restrictive that might apply to anybody; only by using code which does:
SET ROLE rolename;
will the user be able to do more extended operations.
> Currently all of our security on the databse is built into
> the 4GL applications and the database itself is pretty much unrestricted.
Oops! So an ISQL or DB-Access user can wreak havoc on your DB? Bad news.
> However, we would like to put some of the information on the web without
> compromising security, which means the database will have to become
> protected.
It certainly will!
Make sure the public privileges are very very tight. Try to ensure that
the web-users access the database as some equally under-privileged user.
Have fun.
Yours,
Jonathan Leffler (johnl@informix.com) #include <witticism.h>