>> One common misunderstanding is the way roles work. You can make a user
>> a member of multiple roles, but they can only login under only ONE
>> role at a time. While logged in under that role, they can do whatever
>> that role permits BUT they cannot do anything else - even though they
>> may also be a member of a different role that does have the necessary
>> permission.
>Personally, I prefer to call these 'groups'. And I would very much like
>to see them appear in InterBase/Firebird.

They already do! They work with UNIX Groups. Windows doesn't implement anything like it, really. The ACL in Windows is a big crock, IMO but, FWIW, I'm pretty sure Project JEDI has both a Delphi translation of the API and some encapsulating routines in the JCL...


