weird SELECT privilege issue

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • shsandeep

    #1

    weird SELECT privilege issue

    I have given 'SELECT','INSER T' privileges to a user 'group' for a set of
    tables.

    But a user gets a prompt that he does not the 'SELECT' privilege on that
    particular table. The user does belong to the group which has been granted
    the privileges.
    When I give the privileges to the user (only the user, not the group), it
    works fine.
    He is also able to select the table properly in CONTROL CENTER but he gets
    the error message in Development Center while compiling a SP.

    Any idea for this strange behaviour??

    Cheers,
    San.

  • Serge Rielau

    #2
    Re: weird SELECT privilege issue

    shsandeep wrote:
    I have given 'SELECT','INSER T' privileges to a user 'group' for a set of
    tables.
    >
    But a user gets a prompt that he does not the 'SELECT' privilege on that
    particular table. The user does belong to the group which has been granted
    the privileges.
    When I give the privileges to the user (only the user, not the group), it
    works fine.
    He is also able to select the table properly in CONTROL CENTER but he gets
    the error message in Development Center while compiling a SP.
    >
    Any idea for this strange behaviour??
    DB2 does not consider groups for static SQL because it can't track
    membership changes. Could that be it?

    Cheers
    Serge
    --
    Serge Rielau
    DB2 Solutions Development
    IBM Toronto Lab

    IOD Conference

    Comment

    • Pierre Saint-Jacques

      #3
      Re: weird SELECT privilege issue

      That is exactly it.
      It is stated in the docs. that when you have bindadd privileges (to build
      packages) you are required to have the EXPLICIT privilege to do all
      statements in it.
      Group membership is IMPLICIT save for PUBLIC which is ECEXPLICIT.
      Regards, Pierre.

      --
      Pierre Saint-Jacques
      SES Consultants Inc.
      514-737-4515
      "Serge Rielau" <srielau@ca.ibm .coma écrit dans le message de news:
      4qan45FlfmvbU1@ individual.net...
      shsandeep wrote:
      >I have given 'SELECT','INSER T' privileges to a user 'group' for a set of
      >tables.
      >>
      >But a user gets a prompt that he does not the 'SELECT' privilege on that
      >particular table. The user does belong to the group which has been
      >granted
      >the privileges.
      >When I give the privileges to the user (only the user, not the group), it
      >works fine.
      >He is also able to select the table properly in CONTROL CENTER but he
      >gets
      >the error message in Development Center while compiling a SP.
      >>
      >Any idea for this strange behaviour??
      DB2 does not consider groups for static SQL because it can't track
      membership changes. Could that be it?
      >
      Cheers
      Serge
      --
      Serge Rielau
      DB2 Solutions Development
      IBM Toronto Lab
      >
      IOD Conference
      http://www.ibm.com/software/data/ond...ness/conf2006/

      Comment

      • shsandeep

        #4
        Re: weird SELECT privilege issue

        But there are other procedures running without these errors.
        So far, all privileges have always been given to the 'group' and never the
        individual user.

        Cheers,
        San.

        Comment

        • Serge Rielau

          #5
          Re: weird SELECT privilege issue

          shsandeep wrote:
          But there are other procedures running without these errors.
          So far, all privileges have always been given to the 'group' and never the
          individual user.
          Maybe these procedures are using dynamic SQL (PREPARE/EXECUTE)

          Cheers
          Serge

          --
          Serge Rielau
          DB2 Solutions Development
          IBM Toronto Lab

          IOD Conference

          Comment

          • Serge Rielau

            #6
            Re: weird SELECT privilege issue

            Serge Rielau wrote:
            shsandeep wrote:
            >But there are other procedures running without these errors.
            >So far, all privileges have always been given to the 'group' and never
            >the
            >individual user.
            Maybe these procedures are using dynamic SQL (PREPARE/EXECUTE)
            Further are you sure that these procedures were created by the same user
            and not the DBA?

            --
            Serge Rielau
            DB2 Solutions Development
            IBM Toronto Lab

            IOD Conference

            Comment

            Working...