TurboIMAGE/XL Database Management System Reference Manual MPE/iX V6.5 (30391-90011)

Chapter 2 55
Database Structure and Protection
Protecting the Database
In summary, the database designer can grant access to a data set in the following ways:
Specify the user class number in the data set read class list (or omit both read
and write lists entirely). This grants the user class read access to the data set that is
controlled at the data item level as described later. If both read and write class lists are
absent, the user class is granted this type of access because the lists are (0,1,2,...63/) by
default. Opening the database in access mode 2, 5, 6, 7, or 8 is the same as specifying
the user class number in the data set read class list only.
Specify the user class number in the data set write class list. If the database is
opened in access mode 1, 3, or 4, this grants the user class complete access to the data
set. Users in this class can add and delete entries, update the value of any data item,
and read any item, regardless of the data item read and write class lists. Master data
set key item values cannot be updated. Detail data set search or sort item values can be
updated if permitted by the critical item update (CIUPDATE) option settings for the
database and the current process. A user class number must be in the data set write list
in order to add and delete entries. For information about critical item update
(CIUPDATE), refer to chapter 4.
Exclude the user class number from both the specified read and write class
lists of the data set. This denies the user class any type of access to the data set.
Table 2-3. Enabling a User Class to Perform a Task
Task Database
Access Mode
Data Set\Security Rules Data Item\Security Rules
Read Data
Item
1, 3, or 4 User class must be in data
set write list, or
User class must be in data
set read list and pass data
item security.
User class must be in read or
write list.
2, 5, 6, 7, or
8
User class must be in data
set read or write list and
pass data item security.
User class must be in read or
write list.
Update Data
Item
1, 3, or 4 User class must be in data
set write list, or
User class must be in data
set read list and pass data
item security.
User class must be in write
list.
2 User class must be in data
set read or write list and
pass data item security.
User class must be in write
list.
Add or Delete
Data Entries
1, 3, 4 User class must be in data
set write list.