Subject | Re: [ib-support] dynamic roles |
---|---|
Author | Ann W. Harrison |
Post date | 2001-12-31T15:03:15Z |
At 03:48 PM 12/30/2001 -0500, Mike Arace wrote:
to the database at all. The application connects so neither the
user name nor password is ever visible outside the trusted server.
client or between the application and the database.
Ann
www.ibphoenix.com
We have answers.
>1) a user is created with no permissions to do anythingOK.
>2) said user can log in through an applicationOK
>3) some library is used to assign a predetermined role for that user whichHow does it decide what role to use?
>is only good for the current connection,
> which prevents people from loggingI don't see how they could do that... The client doesn't connect
>in through the app and then opening up a new connection directly to do their
>damage.
to the database at all. The application connects so neither the
user name nor password is ever visible outside the trusted server.
>4) when the connection is closed, this role information is lostWhich connection? The connection between the application and the
client or between the application and the database.
>The system I am thinking of would be a web based application that would allRegards,
>be on trusted servers. I'm trying to handle all of the user features on the
>application level, using one database login to make the connections and
>query and insert. My concern is that someone who could figure out that one
>login could have a field day with the information in the database, if they
>could somehow reach it. As I said before, someone who can get to the box
>can do lots of other nasty things as well, which would also have to be
>protected against. I was just wondering if these facilities already exist
>in FB.
>
>Regards,
>Mike
>
>_________________________________________________________________
>Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp.
>
>
>
>To unsubscribe from this group, send an email to:
>ib-support-unsubscribe@egroups.com
>
>
>
>Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
Ann
www.ibphoenix.com
We have answers.