RE: table level Permissions - Usage of 'PUBLIC'
Posted in 2000
This message is in MIME format. Since your mail reader does not understand this format, some or all of this message may not be legible. ------_=_NextPart_001_01BFCBEC.2968D11E Content-Type: text/plain; charset="iso-8859-1" Won't make any difference. The engine will give the user the 'widest' possible access. If you "grant select,update,insert,delete to public on a table", then *ANYONE* and *EVERYONE* that can CONNECT to the database will have those permissions, regardless of any other specific privileges on that table. Have you looked into using ROLES? Other than that, yes, you will have to grant specific privileges to specific users, and eliminate or reduce access to 'public' -- but then, you didn't want anyone to say that... ;-) HTH, Paul Mosser -----Original Message----- From: Edward Rosenthal [mailto:edrosenthal@home.com] Sent: Thursday, June 01, 2000 7:59 AM To: informix-list@iiug.org Subject: Re: table level Permissions - Usage of 'PUBLIC' what about revoke index,alter,delete,update,insert on <tablename> from <username> ? if you needed to do this for a lot of users it is fairly easy to write a script to do this... mohdanas@my-deja.com wrote: > Once we grant select,update,insert,delete to public on a table, does > anybody knows how to restrict a single user to have only select > permission. > > Please don't tell me to grant privileges for each individual user for > every table...! > > Thanks and regards > > Mohamed Anas > > Sent via Deja.com http://www.deja.com/ > Before you buy. ------_=_NextPart_001_01BFCBEC.2968D11E Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> <HTML> <HEAD> <META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; = charset=3Diso-8859-1"> <META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version = 5.5.2448.0"> <TITLE>RE: table level Permissions - Usage of 'PUBLIC'</TITLE> </HEAD> <BODY> <P><FONT SIZE=3D2>Won't make any difference. The engine will give = the user the 'widest' possible access. If you "grant = select,update,insert,delete to public on a table", then *ANYONE* = and *EVERYONE* that can CONNECT to the database will have those = permissions, regardless of any other specific privileges on that = table. Have you looked into using ROLES? Other than that, = yes, you will have to grant specific privileges to specific users, and = eliminate or reduce access to 'public' -- but then, you didn't want = anyone to say that... ;-)</FONT></P> <P><FONT SIZE=3D2>HTH,</FONT> <BR><FONT SIZE=3D2>Paul Mosser</FONT> </P> <P><FONT SIZE=3D2>-----Original Message-----</FONT> <BR><FONT SIZE=3D2>From: Edward Rosenthal [<A = HREF=3D"mailto:edrosenthal@home.com">mailto:edrosenthal@home.com</A>]</F= ONT> <BR><FONT SIZE=3D2>Sent: Thursday, June 01, 2000 7:59 AM</FONT> <BR><FONT SIZE=3D2>To: informix-list@iiug.org</FONT> <BR><FONT SIZE=3D2>Subject: Re: table level Permissions - Usage of = 'PUBLIC'</FONT> </P> <BR> <P><FONT SIZE=3D2>what about revoke = index,alter,delete,update,insert on <tablename> from</FONT> <BR><FONT SIZE=3D2><username> ?</FONT> <BR><FONT SIZE=3D2>if you needed to do this for a lot of users it is = fairly easy to write</FONT> <BR><FONT SIZE=3D2>a script to do this...</FONT> </P> <BR> <BR> <P><FONT SIZE=3D2>mohdanas@my-deja.com wrote:</FONT> </P> <P><FONT SIZE=3D2>> Once we grant select,update,insert,delete to = public on a table, does</FONT> <BR><FONT SIZE=3D2>> anybody knows how to restrict a single user to = have only select</FONT> <BR><FONT SIZE=3D2>> permission.</FONT> <BR><FONT SIZE=3D2>></FONT> <BR><FONT SIZE=3D2>> Please don't tell me to grant privileges for = each individual user for</FONT> <BR><FONT SIZE=3D2>> every table...!</FONT> <BR><FONT SIZE=3D2>></FONT> <BR><FONT SIZE=3D2>> Thanks and regards</FONT> <BR><FONT SIZE=3D2>></FONT> <BR><FONT SIZE=3D2>> Mohamed Anas</FONT> <BR><FONT SIZE=3D2>></FONT> <BR><FONT SIZE=3D2>> Sent via Deja.com <A = HREF=3D"http://www.deja.com/" = TARGET=3D"_blank">http://www.deja.com/</A></FONT> <BR><FONT SIZE=3D2>> Before you buy.</FONT> </P> </BODY> </HTML> ------_=_NextPart_001_01BFCBEC.2968D11E--