Re: Permission Problems
Posted in 1997
>From: Jayakumar George <JayaG@unitedgas.co.uk> >Date: Thu, 17 Jul 1997 10:05:26 +0100 >X-Informix-List-Id: <list.15507> > >I wanted to revoke/grant permissions on a table(s) created by another >user. I logged in as informix. But still cannot revoke/grant >permissions. I thought logging in as informix is somewhat like a >super-user in Unix. I tested this in both 5.x and 7.x engines. Is this >the way it should work?. Or am I missing something. I covered this quite recently -- in the last two months -- in c.d.i, so visiting DejaNews (http://www.dejanews.com) or the IIUG archives should help you too. Basically, the manual says that only the grantor of a permission can revoke it. Unless user informix granted the permission, user informix cannot use REVOKE to revoke the permission. However, what informix can do is edit the system catalogue -- removing rows from SysUsers (database privileges) or SysTabAuth, SysColAuth, SysProcAuth, etc (other privileges) which donate the privileges. It isn't documented, and therefore isn't supported, of course. And making sure you do it cleanly, especially where WITH GRANT OPTION has been given, is very difficult -- another reason why it isn't supported. It is much better, and much simpler, to login as the user who granted the privileges and to revoke the privileges as the user who granted them. Yours, Jonathan Leffler (johnl@informix.com) #include <disclaimer.h> PS: Warning I do not reply to messages with anti-spam in the return path.