Re: [?] Disallowing updates through ODBC...
Posted in 1994
In article <3cnuqi$if1@kelly.teleport.com> cpilot@teleport.com (Richard Shannon) writes: >Some of the users will be >using the application as well as Q&E ODBC, INET 5.01.UD3 and MS Access >for simple ad-hoc reporting. I am trying to secure the database from >any unfortunate updates while a user is running MS Access. One way to do this is to use a front-end or "wrapper" program to start the application that needs to do the updates. The start-up program changes the real and effective uid, then exec's the application. The target login-ID, call it the application-ID, can be derived in any way that makes sense for your environment. In our case, we add a prefix to the invoking login-ID to get the application-ID. For example, if user "walt" runs the application, the start-up program adds a prefix like "x" to "walt" to get the application-ID "xwalt". It then does a setuid to "xwalt" and exec's the real application. The DBA grants the privileges needed for the application are to user "xwalt", while user "walt" is granted only SELECT on the tables/views he is allowed to see. There are obviously a number of fine points that need to be considered if you want to use this approach. Many of them are covered in the file "appstart" in /pub/informix/pub in the ftp archive on mathcs.emory.edu. That file is a shar file that contains a technical paper and sample code. Good luck, Walt. -- Walt Hultgren Internet: walt@rmy.emory.edu (IP 128.140.8.1) Emory University UUCP: {...,gatech,rutgers,uunet}!emory!rmy!walt 954 Gatewood Road, NE BITNET: walt@EMORY Atlanta, GA 30329 USA Voice: +1 404 727 0648