Subject | RE: [Firebird-Architect] User name SYSDBA |
---|---|
Author | Leyne, Sean |
Post date | 2005-08-04T21:03:11Z |
> >The "problem" that you think exists is very simply addressed by theweb
> >service authenticating a user using one connection (which has accessto
> >only the security data) and then have all other accesses done usingwould
> >having the a new connection created. As such, the new connection
> >be in the users context and thus governed by their specific rights.To be clear, which overhead?
> >
> >
> That, at best, doubles the overhead.
> And if a user has multiple roleswithout
> (say a poster, moderator, and administrator), it doesn't work at all
> since no single role can give the user his full range of access
> the dba being required to define artificial roles to map the artesianActually, I'm not talking about such a model and I think we have gotten
> product of actual roles. And to what end?
our wire crossed.
So, I suggest that we come up with some 'straw man' examples to
illustrate our positions.
I will try to work on this a little later tonight, right now I have some
real work to get to.
Sean