Restict access to certain directory by login user

I realized I posted it in the wrong section... I came straight to here becoz I am using Kerberos for auth. Sorry about that.
Hi all,
I am new to JAAS. I googled around but couldn't find an answer to my question...so here it is.
Is it possible to restrict access to a certain directory by using JAAS? For example I have a folder structure of:
/myapp/user1/printout/
/myapp/user2/printout/
/myapp/user3/printout/
User1 should only be able to access files in his own folder after login... I am writing a web application using JSP+Servlet+Tomcat5.5. The application should list and display files in user's print-scratch area. Any suggestion? Please let me know if there was a better solution.
Thank you,
Henry
Edited by: henryonline on Jul 14, 2008 1:07 AM

Hi Dennis, and welcome to the Discussions!
My guess at this point is that you should drag these files to the Desktop for possible later replacement should it not work, then reboot & setup Networking/Internet again...
/Library/Preferences/SystemConfiguration/preferences.plist
/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist

Similar Messages

  • How to restrict read access to certain document in stellent content server

    Hi,
    We are using stellent content server to store project documents. We would like to restrict access to certain confidential documents.
    Users with Read / Write permission should not be able to access but admins with RWDA permission should be able to access these confidential documents.
    Appreciate your inputs on this.
    Thanks,
    Nayana

    Without seeing your setup and environment its a bit hard..
    But...
    Make sure that user has read only access to public security group.
    You could setup an addition role with readOnly access and apply it those users.
    Or restrict there account to have Read only access.
    Remember if the user has Admin access on the Account but only readonly access on the security group then they will only have read only access on the files and visa versa.. :)
    J.
    Message was edited by:
    JRS

  • How to access Sap portal login user in ejb web service

    Hi,
    I wnt to access SAP Portal login user in my ejb application which resides on the same server.
    I am using following code
    try {
         IUser user =null;                         IWDClientUser wdUser = WDClientUser.getCurrentUser();
                                  user = wdUser.getSAPUser();
                             } catch (WDUMException e) {
                                  // TODO Auto-generated catch block
                                  e.printStackTrace();
    Some additional jar files are required for this?
    The same code works fine with webDynpro but not with ejb.
    Thanks in advance     
    Best regards,
    Nilesh

    Thanks for reply.
    I have already added com.sap.security.api in my EJB module project classpath. How to add the same in EJB application Project (application-j2ee-engine.xml)?
    Best regards,
    Nilesh

  • How to find from the data dict if a user has read access on a directory

    How to find "dynamically" if a user has READ access to a directory object.
    I want to know if there is a data dictionary table that holds if a user/schema has read access to a directory object.
    I know there is an dba_directories table and an all_directories table but they dont give information as to which user has read access granted to the directory.

    Not so difficult.
    select  'YES'
       from all_tab_privs A, all_directories B
       where a.grantee = 'USERNAME'
           and a.table_name = b.directory_name
           and b.directory_path = 'PATH YOU ARE LOOKING FOR'
    How to find "dynamically" if a user has READ access to a directory object.
    I want to know if there is a data dictionary table that holds if a user/schema has read access to a directory object.
    I know there is an dba_directories table and an all_directories table but they dont give information as to which user has read access granted to the directory.

  • File Sharing with user on MacBook Pro, restrict access to certain folders

    I work on my iMac mostly and have 3 external drives hooked into the iMac. I have file sharing turned on because I want to be able to access these external drives on my macbook pro. I can get into all my drives as planned. However, I have a user on the macbook where I want to restrict them from seeing certain folders on those external drives.
    For instance, I have budget documents in a folder on one of those drives along with family photos in another folder. I want this user to be able to access the folder of fam photos but not access the folder of my budget docs. How do I do this?
    I tried "get info" on that specific folder and selected the "write only (drop box)" option and that doesn't work, that user can still open and see all the budget docs. I believe I've even tried removing them from that folder on the "get info" box. Either way, that folder is still accessible for all.
    Please help!!!!!!!

    Response appreciated but the easiest way to handle the problem, is being able to restrict 2 or 3 folders which is what I can't figure out how to do. Maybe there is no way to do this. I have spent a good deal of time organizing the folders in the first place, and with some of these things being related to my business, it would be more of a headache and major issue, to reorganize these folders. Things are very well organized, I just don't want certain users to have access to a couple of the folders as those certain folders have income related and budget related information.
    So my issue is really, not about re-organizing or any of that, but merely, how to I set a folder to where a certain user doesn't have access to that certain folder.
    You wouldn't think that would be too difficult, but then again, maybe it is just something that can't be done. I would think it'd be as easy as opening the "get info" on that certain folder, selecting that user and setting it to say "no access" - however, that is not an option in the drop down and I don't know why. It offers, read & write, read only, write only (drop box). Even when I select write only, it still allows that user to see all my files in that folder and access them. So I'm just not sure why "no access" is not listed there as an option.
    Thanks.

  • Access to certain internet sites/services not working

    A couple of days ago, my access to certain internet sites as well as my Mail programme and another email client app stopped making successful connections. I can open many web pages, but some do not work. Specifically, the local library where I can login to check the online catalogue doesn't work. My Mail app won't connect either. I also use another email app called First Class for work and it can't connect to the online server. If I start up Network Diagnostics and change from Airport or Built-in Ethernet it will work, at least until I quit the app and reboot it, then it can't make the connection. I have checked and replaced cables, removed the Airport and gone direct with Built-in Ethernet, etc. This phenomenon happens with all five user accounts on the computer. Other computers in our home which are connect to the LAN have no such behaviours happening, which leads me to conclude something is not right on the iMac we use all the time.
    Any ideas?

    Hi Dennis, and welcome to the Discussions!
    My guess at this point is that you should drag these files to the Desktop for possible later replacement should it not work, then reboot & setup Networking/Internet again...
    /Library/Preferences/SystemConfiguration/preferences.plist
    /Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist

  • FAQ: BC-LDAP-USR (Directory Interface for User Management via LDAP )

    Version: 20060317
    Q: Where can i find more information to the BC-LDAP-USR interface ?
    A: Have a look on our ICC webpage in the SDN:
    SAP NetWeaver AS - Directory Interface for User Management via LDAP (BC-LDAP-USR)[1] [original link is broken]
    Q: What costs a arising when we want our product to be certified ?
    A: See also our SDN page under the headline "Price List".
    Q: Is there a link/page for the already certified products for this interface ?
    A: Sure, have a look on our ICC page under the headline "Certified Solutions"
    Q: Who can we ask in case of general question ?
    A: Have a look at our general ICC forum:
    SAP Integration and Certification Center (SAP ICC)
    Of course, if you have urgent requests you can send them also directly to our local ICC's:
    ICC Walldorf in Germany: [email protected]
    ICC Palo Alto in USA: [email protected]
    ICC Bangalore in India: [email protected]
    Q: Who can we ask in case of technical questions ?
    A: This depends on the state of your certification project.
    1.) If the certification contracts have been signed then you can ask in this forum and if this does not solve your question go back to your assigned integration consultant.
    2.) When the certification contracts have not been signed then you can ask questions in this forum.

    I distinguish it using the passwordExpirationTime(or something like that, i don't have code here with me).
    This is possible if after password is expired user has at least one more access.It is a user policy that can be set in the Ldap server.
    If it is possible, user can still login and perform operations.You chan search the passwordExpirationTime attribute and determine if password is expired, and the send a message to the user, telling him to change it.(If only one access is allowed and you change the password with the same application or service then do not close context, else you should not be able to connect again.) Instead, if you use an external script, then the last acces should not give you problems.
    Hope i made myself clear.

  • Is it possible access to dashboards by using network users insted of obiee

    Hi,
    can anybody have idea about this
    is it possible access to dashboard by using network users.insted of obiee users.i.ewhen you are login into presentation services it will ask user name and password. in this case it will not like that when we are log in to the sysytem by using user name and password.by using that user name and password it can directly access to the dashboard is it possible or not?means that by using network username and password can i able to login to the dashboard by cliking the presentation url.with out asking username and password again.
    please help me
    thanking you

    Yes, you can and if your presentation services are hosted on a windows server, thats lot more easy. While the presentation server is being promoted, you can have users get authenticated using LDAP/AD and that way, you need not go through typing username/pwd once again.
    Configure SSO
    Set IIS authentication to “Windows authentication”:
    Open IIS Manager => Select Default website => Right-click => Properties => Directory Security tab => Authentication and access contol => Edit … => deselect “Enable anonymous access” => Select “Integrated Windows authentication” => Ok => Ok => Select All => Ok
    Open the instanceconfig.xml file (located in OracleBIData\web\config). Set <SSO enabled = “true”>. Save and close file.
    Restart your server and start your OBIEE services.. You are good to go now.
    Like others said, may be you are better off with closing your questions so others can use it.

  • Error while writing to file: C: \ Program Files (x86) \ iTunes \ iTunes.Resources \ el.Iproj \ iTunesExtrasDownload.png. Make sure you have access to this directory.

    When i try to install iTunes in my Windows 7, this error message apear "Error while writing to file: C: \ Program Files (x86) \ iTunes \ iTunes.Resources \ el.Iproj \ iTunesExtrasDownload.png. Make sure you have access to this directory." Someone help me!!

    That one's consistent with disk/file damage. The first thing I'd try with that is running a disk check (chkdsk) over your C drive.
    XP instructions in the following document: How to perform disk error checking in Windows XP
    Vista instructions in the following document: Check your hard disk for errors
    Windows 7 instructions in the following document: How to use CHKDSK (Check Disk)
    Select both Automatically fix file system errors and Scan for and attempt recovery of bad sectors, or use chkdsk /r (depending on which way you decide to go about doing this). You'll almost certainly have to schedule the chkdsk to run on startup. The scan should take quite a while ... if it quits after a few minutes or seconds, something's interfering with the scan.
    Does the chkdsk find/repair any damage? If so, can you get an install to go through properly afterwards?

  • I receive the following error message when trying to install QuickTime for Windows "Error writing to file C:/Program Files/QuickTime/QTSystems/QuickTimeCheck.ocx. Verify that you have access to that directory."

    I recieve the following error message when trying to install Quicktime for Windows "Error writing to file C:/Program Files/QuickTime/QTSystems/QuickTimeCheck.ocx. Verify that you have access to that directory."  I just trying to get the latest version of iTunes.  Thanks

    "Error writing to file C:/Program Files/QuickTime/QTSystems/QuickTimeCheck.ocx. Verify that you have access to that directory."
    That one's consistent with disk/file damage. The first thing I'd try with that is running a disk check (chkdsk) over your C drive.
    XP instructions in the following document: How to perform disk error checking in Windows XP
    Select both Automatically fix file system errors and Scan for and attempt recovery of bad sectors, or use chkdsk /r (depending on which way you decide to go about doing this). You'll almost certainly have to schedule the chkdsk to run on startup. The scan should take quite a while ... if it quits after a few minutes or seconds, something's interfering with the scan.
    Does the chkdsk find/repair any damage? If so, can you get an install to go through properly afterwards?

  • Itunes will not install. I get the error message "Error writing to file: C:\Program Files\Common Files\Apple\Mobile Device Support\com.apple.IE.client_main.dll     Verify that you have access to that directory."

    Itunes will not install. I get the error message "Error writing to file: C:\Program Files\Common Files\Apple\Mobile Device Support\com.apple.IE.client_main.dll     Verify that you have access to that directory."

    That one's consistent with disk/file damage. The first thing I'd try with that is running a disk check (chkdsk) over your C drive.
    XP instructions in the following document: How to perform disk error checking in Windows XP
    Vista instructions in the following document: Check your hard disk for errors
    Windows 7 instructions in the following document: How to use CHKDSK (Check Disk)
    Select both Automatically fix file system errors and Scan for and attempt recovery of bad sectors, or use chkdsk /r (depending on which way you decide to go about doing this). You'll almost certainly have to schedule the chkdsk to run on startup. The scan should take quite a while ... if it quits after a few minutes or seconds, something's interfering with the scan.
    Does the chkdsk find/repair any damage? If so, can you get an install to go through properly afterwards?

  • How to prevent/allow admin access from certain ip address.

    Hello
    trying to setup the following scenario:
    have a user BOB created in Cisco ACS 4.2
    have several network devices with different management IP addresses  all added in Cisco ACS 4.2
    want to be able to allow BOB to access network devices only if BOB's access request is coming from one ip address 1.1.1.1
    If BOB is trying to access network devices from any other ip addresses, the request should be denied regardless of the fact that BOB has full access to all network devices.
    Is there a way to acomplish this using Cisco ACS 4.2
    Appreciate your input.
    Regards,

    It is actually possible, thanks for your doc reference:
    in ACS setup AAA client user will be allowed to call from
    in ACS setup NAR (devices you want to allow access to);
    create user in ACS
    configure user access in ACS:
         allow access to required NARs
         define IP - based access restrictions
              Permitted calling / point of access locations
                   enter AAA client from which user will call (* for ports and * for ip address)
    Save and test
    In failed attempts you should see Authentication failure code "Users access filtered" when trying to login to NAR devices with new username and from non-permitted calling client/ip address.
    Thanks for you help.

  • How do I limit access to certain (but not all) applications on my laptop?

    Hello,
    Is it possible to reduce access to certain applications (eg Email) while allowing other applications to remain "open" to all users?
    I only have one account on my powerbook, and would like to simply prevent access to certain applications.
    Any help will be greatly appreciated,
    thank you,
    nihal

    Korelice
    you would need , in following Matt's advice to ensure that the restricted users were not created as admin users. That is, on creation do not click the 'allow this user to administer computer' box. If you tried parental controls on them, you would be told by the OS that you can't restrict an admin.
    The better advice would be to restrict the actual use of the single user you have now, who is presumably an admin, to just admin (installations, re configs, set up new users etc) tasks. Change his password so those real people you don't trust (?) couldn't get to him. You could have a 'restricted' user who is not restricted in respect of apps (email, browser etc) but can't admin. Use him yourself for browsing etc and general use. Add another restricted user for(the kids, irresponsible friends and such) who are not admins and can only use certain apps. I am aware that is not precisely what you asked.

  • How to restrict AS02 access to certain fields only

    How to restrict AS02 (Asset Master Record) access to certain fields only. Currently when you assigned AS02 to a certain user, this will enable the user to change all the fields in the asset master record. Suppose i want only the user to restrict the access to certain field eg.NDJAR (Life in Yrs).
    Thanks for your inputs.
    Regards,
    Robert

    hello,
    basis has to assign the proper activity with object A_S_ANLKL. in this case they have to allow activity 03 only with combination of Cocode,asset class. see some more details below.
    This authorization object is the first part of the object "asset master record."
    The definition at this level determines whether the user is authorized to process data in a given company code. The activity type for the transaction is also defined here. This authorization object is used for master data transactions, for the display of value fields, and for reporting.
    Defined Fields
    The following fields are assigned to the authorization object
    Asset class (specified by entering a value in the pop-up window)
    Company code (specified by entering a value in the pop-up window)
    Activity type - there are three different activity types:
    01 = Create
    02 = Change (including blocking and deleting)
    03 = Display

  • Error 1310. Error writing to file....Verify that you have access to that directory

    Hi
    My system is running Win 7 Professional 32 bit with 4gig RAM
    I am experiencing a problem installing a piece of software - Laplink PC Mover - I need to migrate to my new machine.
    The installer starts and the grinds to a halt with the error message:
    "Error 1310. Error writing to file: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Laplink PCMover Professional\Visit Laplink.com.url. Verify that you have access to that directory"
    I understand from Laplink Tech Support that this is a generic Windows Installer problem, and searching the web it seems to crop up a lot.
    I have done a lot of searching, including this site.
    I have tried the solutions I have found so far:
    Run as Administrator [my user profile has administrator rights but I tried that anyway]
    Run from the Administrator user account
    Install in Safe Mode - Windows tells me the installer is not available in safe mode!!!
    Un-registering and re-registering the installer via msiexec
    Using the SubInACL tool to repair file and registry permissions
    After all of this, I get the same result - the installer halts with the same message.
    Can anybody help? I am desperate to avoid two days solid re-installing all my expensive software, finding product keys etc.

    Hi,
    You can test in Clean Boot mode to avoid the software conflicts, in experience, some anti-virus program would lead this corruption.
    Alex Zhao
    TechNet Community Support

Maybe you are looking for