RE: Run 4GL Program without Database Permissions?
Posted in 1996
Richard, another thought: create a fake user with minimal privileges on DB (2), create a 4gl program (for clarity' sake, let's call it Update_DB_2) that does the inserts you need, and make users in group (1) temporarily su to fake_user and run it. You can probably do this rigth from within the program that manages DB(1) by creating a report that pipes the appropriate info (e.g. patient name, date & time in pain dept, etc, etc) to the Update_DB_2 program (haven't tested this so forgive me if this is false info), like thus. start report update_db_2 to pipe "su fake_user -c update_db_2.4ge" output to report(.... etc... Other than that, consider creating synonyms in DB (1) for the tables in DB (2) that needs data insertion, granting users in group (1) minimal privileges (possibly, insert only). Note that roles wouldn't solve your problem anyway, becouse you would have to 1) create a role 2) grant privileges to the role 3) grant role to user 4) set role whenever user needs privilege does this help? marco ____________________________________________________________________________ rem radioterapia, which I immeritately manage, seldom agrees with what I say marco greco (Catania, Italy) Work: marcog@ctonline.it rem radioterapia 39 95 447828 fax 446558 (was mar.greco@agora.stm.it) Achea 39 95 503117 --- On 3 Sep 1996 14:02:05 GMT Richard Spitz <spitz@GANS2X.ana.med.uni-muenchen.de> wrote: Dear Informixers, please help me with the following problem: In our department, we have, among others, two groups of applications with their own databases behind them: 1) Management of the operating room schedules 2) Management of the pain therapy department So far, both have been used by completely distinct groups of users who have nothing to do with each other, especially not with each other's databases. There are about 25 users defined for database (1) and about 15 for (2). Now I need to write a program so that a user of the OR scheduling program can automatically notify the pain dept. of a patient undergoing postoperative pain therapy. This means that a user out of group (1) must be able to invoke a 4GL program with write access to database (2). What I must avoid is having to grant these users any privileges for data- base (2). This is rather awkward to handle in Online 5.0x and a lot of work to keep up to date, since there are no "roles". When I experimented with the "s"-Bit, I got the error message: dynamic linker: postop.4ge: can't find lib4gl.1 Killed However, LD_LIBRARY_PATH is set correctly, and other 4GL programs without the "s"-Bit set can be run without problems. What's wrong? Any suggestions about how my problem could be solved? Regards, Richard -- +----------------------------+-------------------------------------------+ | Dr. Richard Spitz | INTERNET: spitz@ana.med.uni-muenchen.de | | EDV-Gruppe Anaesthesie | Tel : +49-89-7095-3413 | | Klinikum Grosshadern | FAX : +49-89-7095-8886 | | 81366 Munich, Germany | | +----------------------------+-------------------------------------------+ -----------------End of Original Message-----------------