Re: User privilege
Posted in 1997
In article <5eckc1$92p$1@storm.worldnet.net>, Pralay Dutta Gupta <sinfo@univ-paris8.fr> wrote: >Hi informixers! > >Does anybody know whether it's possible to grant data based >privileges to users of On-line 7.10 UD1 ( isql version 6.02 UC1 ) ? > >To be more explicit, let me say, I've got two groups of users; both >using the same tables. Now, I want to grant privileges to one group >only on the data which they're in charge of. In other words, I would >like to grant row level privileges. > SOLUTION 1 : Simple, sweet, some restrictions! Keep separate databases (identical structures) for each group. (We actually do this in our organisation!). Of course, this assumes that you rarely use the information together. However, if you do, you can access both chunks of data in a single query. Unfortunately, while you can make a view accessing external databases, you cannot make a UNION view. SOLUTION 2 : Complex, ugly, some questions, but may be worth a thought! Condition : There must be a column in the table, the value of which identifies each group. Step 1 : Use the FRAGMENT clause in the CREATE/ALTER TABLE with a WHERE clause so that the table fragments represents individual groups. (the column in the 'Condition' would be used). Step 2 : Use the GRANT FRAGMENT clause to restrict access. (N.B. This does not restrict SELECTs) I'd be interested to know what you finally implement. Cheers. ---------------------- Rudy Fernandes GIC, Kuwait ----------------------