Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Users cannot get other users` full names (First Midlle Last), except theit own [CORE1085] #1506

Closed
firebird-automations opened this issue Jan 11, 2007 · 4 comments

Comments

@firebird-automations
Copy link
Collaborator

Submitted by: Rosen Ivanov (rosen_pi)

We have a system based on Firebird 1.5.x. After migration on 2.0, users of the application could not see other user's full names except their own.
When I try to get user info for all users the result is only for currently logged user.
Can I do this in other way, or it will be done i next versions.
Best regards!
Firebird team is the best!!!

@firebird-automations
Copy link
Collaborator Author

Commented by: @AlexPeshkoff

Ability for any non-privileged user to get information about all users (including gettin full logons list) was a security risk in FB1.X. Having list of all users makes it much simpler to attempt brute force attack to guess someone password (without that list one must know logins). This is the reason for letting only sysdba to get full users list.

But restriction is implemented only at SQL level in security2.fdb. Therefore you may easily change VIEW USERS if you really want to open access to all users list.

@firebird-automations
Copy link
Collaborator Author

Modified by: @AlexPeshkoff

status: Open [ 1 ] => Resolved [ 5 ]

resolution: Won't Fix [ 2 ]

@firebird-automations
Copy link
Collaborator Author

Modified by: @pcisar

status: Resolved [ 5 ] => Closed [ 6 ]

@firebird-automations
Copy link
Collaborator Author

Modified by: @pcisar

Workflow: jira [ 11492 ] => Firebird [ 15487 ]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant