[ 
https://issues.apache.org/jira/browse/DERBY-2207?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12563673#action_12563673
 ] 

Dag H. Wanvik commented on DERBY-2207:
--------------------------------------

Re: changing current role after a prepare of a statement.

I am working on code to register dependencies of prepared statements (or just 
the activation?)  as well as triggers, views and constraints, of one (or more) 
roles being depended on (for the authorization check to succeed), cf. 
discussion in DERBY-3223.

I think the changing of the current role (or dropping of a role which the ps 
depends on) should invalidate the (activation of) the prepared statement
here, forcing a re-check at the second execute.


> Improve usability of Derby's client/server security by implementing ANSI Roles
> ------------------------------------------------------------------------------
>
>                 Key: DERBY-2207
>                 URL: https://issues.apache.org/jira/browse/DERBY-2207
>             Project: Derby
>          Issue Type: New Feature
>          Components: Security, SQL
>            Reporter: Rick Hillegas
>            Assignee: Dag H. Wanvik
>         Attachments: spec.html, spec.html, spec.html, spec.html, spec.html, 
> spec.html
>
>
> Implementing ANSI Roles will make it easier to manage security for multi-user 
> applications with high user turnover.

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.

Reply via email to