Firebird Server ↔ Jaybird JDBC: DatabaseAccess Restriction Impact on Connection Paths
0 reputation · 06 Jun 2020, 22:14 UTC
Goal: Ensure that a Jaybird JDBC connection string that works on a local development Firebird instance also succeeds in a production environment where the server runs under a restricted account and enforces the DatabaseAccess restriction.
Constraint: In Firebird 3.0+ the default DatabaseAccess setting is 'Restrict', limiting the server to directories listed in the configuration. A path that is permissible on a developer workstation (often because the server runs with elevated privileges or the setting has been overridden) may fall outside the whitelist in production, causing an 'unavailable database' error. The documentation does not give a clear migration path for existing applications that rely on arbitrary database locations, and it remains unclear how DatabaseAccess interacts with the ExternalFileAccess parameter for external tables and UDFs.
- Should administrators set DatabaseAccess to 'Full' to retain compatibility, or maintain a whitelist approach for security?
- How does the DatabaseAccess setting affect ExternalFileAccess when accessing external files from stored procedures or UDFs?
- What configuration strategy is recommended when upgrading from Firebird 2.5 (where DatabaseAccess=None) to 3.0+ while preserving existing application behavior?