Subject RE: [ib-support] User Management
Author Martijn Tonies
Hi,

> I'm planning to secure my app a little and thought about starting with
> user management.
> Currently my app connects with predefined username and
> password that is
> in crypted form stored into app. The users names and passwords are in
> USERS table. Now I thought to change it - SYSADM will create new
> Interbase users, who will connect to database by entering
> their name and
> password (my app gives them specified ROLE). Are there any pitfalls in
> this approach?

We use the same approach - IB names and an application role assigned to the
users.

What we are planning to change now, is to automatically add a pre- and/or
postfix to the username and/or password so when they would download a copy
of IBConsole, they still don't have a valid username/password combo to enter
the database and destroy it :)

Martijn Tonies
InterBase Workbench - the developer tool for InterBase and Firebird
http://www.interbaseworkbench.com


[Non-text portions of this message have been removed]