Jump to content
Changes to the Jaspersoft community edition download ×

Forbid user to use certain SQL statements?


MiditecReportDev

Recommended Posts

Hi,

 

just wanted to ask if it is in any way possible to forbid the guy who builds the reports to use certain sql statements such as insert, update or delete?

As far as I can see a report tool such as Jasper should have some tools for that as normal reports in my/our eyes should be read-only oO It is kind of unsafe to allow that, especially when the guy who builds the report (theoretical scenario) may get fired, knows it and inserts a delete statement for a crucial database table into a report without anyone being abtle to stop this.

Link to comment
Share on other sites

  • Replies 4
  • Created
  • Last Reply

Top Posters In This Topic

The development is not a problem, we have development databases^^ So deleting from there or looking at data is no problem at all.

Problem is that you can easily give reports to customers that will delete all their data as long as you know at least one table name, which you do since they'll need to tell you for select statements anyways.

Kind of unsecure in my opinion, but we'll solve this differently now.

Link to comment
Share on other sites

  • 3 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×
×
  • Create New...