Actually, when you convert an account to a schema you can use SQL security
to do this.  This is what I am referring to.  You need to setup SQL users
in your schema (same login used to get into UV) or set privileges for
PUBLIC.  If the user exists in the Schema user table then those
permissions are used otherwise the PUBLIC setting is used.  Note that you
can use an account as both a schema and a regular account. This is the
reason I needed to set all permissions for PUBLIC.

I have done this under Universe to provide some basic security related to
using Uniobjects in the past. I am not sure if this will fully solve the
issue being discussed here or if Unidata would behave the same way.

Rich Taylor | Senior Programmer/Analyst| VERTIS
250 W. Pratt Street | Baltimore, MD 21201
P 410.361.8688 | F 410.528.0319 
[EMAIL PROTECTED] | http://www.vertisinc.com
 
Vertis is the premier provider of targeted advertising, media, and
marketing services that drive consumers to marketers more effectively.
 
"The more they complicate the plumbing
  the easier it is to stop up the drain"
 
- Montgomery Scott NCC-1701

> 
> Richard:
> 
> Am I accurate in thinking Pick __USED__ to have file level security but
it
> doesn't exist in the U2 products because, it was always said, the O/S
> takes
> care of security (aka: "we don't need no stinkin file level security")!
> Perhaps, having dbms security isn't such a bad idea after all.  :-)
> 
> Bill
> 
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On Behalf Of Richard Taylor
> Sent: Friday, May 27, 2005 8:09 AM
> To: [email protected]
> Subject: RE: [U2] Uniobjects hack
> 
> [snipped]
> 
> 2) Convert the account to an SQL schema.  You can then attach file level
> security via the SQL user.  Just remember to create a security entry for
> Public too otherwise you could end up locking out all the other users
that
> are not subject to the tighter security. (i.e. GRANT ALL TO PUBLIC)
> 
> If you are trying to allow them to access a file, but control what they
do
> you may be out of luck.  However you could use triggers to a least
create
> audits.
-------
u2-users mailing list
[email protected]
To unsubscribe please visit http://listserver.u2ug.org/

Reply via email to