HELP With security requirement

Dear All,
I�ve been working with J2EE for a while and now i am facing a requirement I assume J2EE can face but I would like some professional orientation.
I�m developing a financial systema, Web & server, using GalssFish. The requirement I have is that "any system service" as I call the operations accessible from the client (web app) should be permission secured, that means, that for each User or Role, I sould be able to configure wich system services it can access ( at least) or more in depth wich level of security it has.
Roles are not fixed, the sysadmin should be able to configure any Role, and assign to it any User, what is fixed are the system services. The permissions to each role for system service access should be configurable.
I hope the explanation is understandable,
Can anyone help me in order to assume this is possible with glassfish, and where could I read something nearly close to what I need (i�ve read JEE tutorial, and a buch of papers of security in EJB and Web tier but none provides information for my requieremtent).
Regards,
Germ�n Viera.

Marco,
One place you could put additional auth-check for you custom table is SE11 -> Utilities -> Table maintenance generator -> Environment -> Modification -> Events.
I believe Event 25 is for inserting Auth-Check on table fields.
Hope this help.
Lye

Similar Messages

  • Help with Secure Erase

    I need help with Secure Erase 7-pass in the utility disk. It keeps getting stuck at 25% and a pop up comes out saying not enough memory in the start up disk. Can someone tell me whats going on? After the pop up come on the erase will not proceed.

    Hello,
    moving files from your computer
    You can delete files, folders, and other items on your disk that you no longer need.
    You may want to store a backup copy or an archive of important items if you are trying to clear space on your hard disk for other things.
    Drag the items to the Trash (at the end of the Dock).
    Any files or folders you drag to the Trash remain there until you empty the Trash. If you change your mind about something, you can still retrieve it from the Trash if you haven't emptied it yet. Click the Trash icon to open the Trash window, then drag items back to your home folder.
    Choose Finder > Empty Trash.
    Even after you empty the Trash, deleted files may still be recovered by using special data-recovery software. To delete files so that they cannot be recovered, choose Finder > Secure Empty Trash. Files deleted in this way are completely overwritten by meaningless data. This may take some time, depending on the size of the file. To prevent the recovery of files you deleted previously, open Disk Utility (in Applications/Utilities), choose Help > Disk Utility Help, and search for help on erasing free disk space.
    If an item is locked, you cannot put it in the Trash. Select the item and choose File > Get Info, then deselect the Locked checkbox in the General pane. If you do not own the item, you may need to provide an administrator's name and password to put the item in the Trash.
    Press the Option key when you choose Empty Trash to prevent the warning message from appearing. You can also turn off the warning in the Advanced pane of Finder Preferences.
    Also... using the Erase Free Disk Space button:
    Erasing free disk space
    When you delete files by emptying the Trash, Mac OS X deletes the information used to access the files but doesn't actually delete the files. Although the disk space used by deleted files is marked as free space, deleted files remain intact until new data is written over them. Because of this, deleted files can be recovered.
    You can use Disk Utility to erase the "free" space used by deleted files by having zeros written over the space once, seven times, or 35 times. If you have a lot of free space on your disk, overwriting the free space several times can take a long time.
    Erasing free disk space does not erase the other files on your disk.
    In Disk Utility, select the disk or volume in the list with the free space you want to erase.
    Click Erase, then click the Erase Free Space button.
    Select an option, then click Erase.
    After the process begins, you can interrupt it without harming your data.
    You might see a message saying that you are running out of disk space, but you can ignore that warning. When this operation is complete, you will have the same amount of free space as you did when it started.
    You can also erase free space when you empty the Trash in the Finder. Choose Finder > Secure Empty Trash.
    Carolyn
    Message was edited by: Carolyn Samit

  • Need help with security

    Hi. I'm new to this list, and pretty new to web services. I'm
    currently trying to apply security to an existing application, and
    i've been studing the tutorials at sun web
    (http://java.sun.com/webservices/docs/1.4/tutorial/doc/). In the
    simple sample, in the build.xml file, there's a 'gen-server' target
    which i believe creates ties of the service, right? Well, i do the
    same step in my application (just before packaging into a raw war
    file), and move all the generated files, together with my server
    compiled classes, to the WEB-INF dir. Therefore i have all that class
    files in /WEB-INF/classes/hello (i'm doing this with a helloword
    example). Included in those files, theres a file called
    "HelloIF_Tie.class", which i assume is the tie for my service, created
    by the 'gen-server' target.
    After this i create a raw war file using the jar tool, and take the
    generated file to a dir named "dist". Then i try to create a cooked
    war file using the wsdeploy tool. However when i try to run the
    application, the server seems to ignore any security options i have
    configured. Looking into the deployable war file i found that it had
    generated quite a few more class files
    (HelloIF__HelloService__Tie.class between them), and that in the
    jaxrpc-ri-runtime.xml file there was the following line:
    tie='hello.HelloIF__HelloService__Tie'
    This seemed a bit strange to me, since i believed that my tie file was
    HelloIF_Tie.class. Therefore, i tried something: changing that line
    for
    tie='hello.HelloIF_Tie'
    And packaging all into a war file again with the jar tool, everything
    runs fine. However its kind of boring doing this every time i change
    the server code. So my question is...
    is it possible to tell the wsdeploy tool not to generate any tie
    files, and use the ones existing in the raw war file???
    is there any other solution to my problem???
    Im sorry if these questions are stupid, but im still quite novice with
    jwsdp and i dont know if im doing things right. Thank you very much.

    CQAndroid, help is here! I am familiar with this feature and use it with my own laptop and iPhone and well. It's a great feature! It forwards all of your text messages to your phone and Macbook, if you like. There's a few steps to try. First go to your iPhone Messages settings (Settings > Messages > iMessage) and turn off iMessages and turn it on again. Then go to the iMessages Settings on your Mac and do the same. Also make sure to activate your telephone number in the iMessages settings on your Mac. Try this and keep us posted please. Thanks!
    KristieQ_VZW
    Follow us on Twitter @VZWSupport
    If my response answered your question please click the "Correct Answer" button under my response. This ensures others can benefit from our conversation. Thanks in advance for your help with this!!

  • Help with Security Scenario

    Hi, I have a security scenario I am hoping someone can me help with.
    Right now a user is authorized to "Sales Office" 100 only. 
    In the below scenario I need the user to be able to:
    1. See Transactions where the "Sales Office" is 100
    2. See Transactions where the "Sales Office of the Ship-To" is 100 even if they don't have access to "Sales Office" value. 
    So if the "Sales Office" is not 100, but the "Sales Office of the Ship-To" is 100 then they should see that as well.
    Access
    Sales Office
    Sales Office of Ship-To
    Yes
    100
    200
    Yes
    100
    201
    Yes
    200
    100
    No
    200
    300
    No
    300
    310
    Yes
    400
    100
    Yes
    300
    100
    Yes
    100
    100
    Note: Sales Office of the Ship-To is a Navigational Attribute of Ship-To Customer and is the same characteristic as "Sales Office"
    Is there any way to accomplish this with 7.x Analysis Authorizations or any other method?

    Hi,
    Yes it's possible, check details in the document below :
    http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/7052dee3-bce5-2d10-5299-cd5d00ebeb72?quicklink=index&…
    hope it helps.

  • Need help with security design!

    Hi,
    I haven't worked with security design very much. Currently I'm about to develop an application to my father which should implement some sort of security.
    One of the reasons for this application besides making my father happy is educating myself.
    The application is an online image album.
    The security could be divided in role-based security and instance level security.
    Role-based (NO PROBLEM):
    A user cannot delete another user, an administrator can delete users.
    Instance-level (DON'T KNOW HOW):
    A user can load other users image albums if he/her is allowed/granted to view the album and its images. Note that the user could be granted to view the album, but not all of its images.
    My problem is how I should design the "instance-level" security? Should I keep a ACL (Access Control List) with each instance of album and image?
    This seems to be a common functionality to add view/load/read/write permissions to an instance in runtime to let a certain user to operate on an asset?
    Have searched the Internet but haven't found any nice framework to help me.
    Could anyone with some experience please help me out?!
    Kind regards, Andreas

    Hi,
    I ran into the same problem. Could you resolve it?
    please give me your feedback.

  • In Desperate need for help with Security Settings

    I am currrently working on a project that requires a Flash
    submenu running through an HTML Browser window and running from a
    CD. The problem is that the final destination for these CDs will be
    on computers without the capability to connect to the internet. So,
    when the user gets the popup requiring them to change the security
    setting in order to use the flash element, which is through the
    internet (the dumbest way of doing this) they have no choice but to
    decline the popup and therfore cannot use the flash submenu.
    Is there a way to automatically be trusted whitiout the use
    of the internet "security settings" window???????? If anyone from
    Adobe/Macromedia read this please be advise that this should really
    change to be computer based and not requiring an internet
    connection.
    If this is esay enough to change, I regret everything that I
    am thinking of about Adobe/Macromedia at the time I writing this.
    and please acceot my apologies.
    If not, well.....
    Thanks for anyones help.

    When Exporting, you get the option of setting the Local
    Playback security (very bottom of the Export dialogue box). Have
    you checked to make sure you have yours set to "Access local files
    only"?
    What is the submeu trying to access that would cause the
    sandbox warning?

  • Help with secure zone/ forum registration

    Im having difficulty grasping the secure zone concept and ive spent days watching videos and reading online so I hope someone can help push me forward.
    I built the site with Muse, and im using dreamweaver and the BC site (older view) to help edit.  I have a creative cloud subscription.
    First I want to create a registration page to collect custom information on users, for example:  The site is about traveling, so I want users to be able to select which countries they have visited, upload a photo, and control their own profile.
    I want this user information to control the forums, their own blog, and their own photo galleries.
    I'm not afarid of doing the work it till take to get this done but I dont understand if I need to use webforms,  or web app.  The forums module has a default registration page that is very basic, can I use that for a template and just expand it? 
    Also I attempted to make webforms and use them, however when I publish my site live again in muse, it seems to delete any forms I made in BC, do I need finish using muse and stay away from it now that the basics are complete?
    Thanks for your help, and any leads or overall concepts that I am missing would be great!  Thanks!

    You can not do that in BC exactly. It is not designed for that sort of site.
    You can not use the CRM to build that sort of thing.
    You will need to build a blog with webb apps and allow them to submit their own and edit their own web app items. For the forums you have a login for the forums but you can not have their own indevidual forum.
    Photo gallery - not using the BC module and will again have to be a web app and limited.
    To pull that into a public profile you again can not use the CRM as showing their CRM information is ONLY when THEY are logged in. You would have to replicate their data in another web app. And pulling them together will be hard unless you know ajax etc and still complicated.
    You probably better off using a different platform to achieve what your after. Coming from Muse and what that outputs as well your going to have a hard time of it. You can not use Muse to publish if you want more stuff like this because it will just do an all in one publish. If you do stick with BC you have to now Ditch Muse if you watn to do any of this right and more.

  • Help with Secured Documents!

    I have been using the same files for over a year with no issues. Up until today I was able to edit them with no problems. All of a sudden when I go to use a document I receive an error message stating that
    "The security settings on this document prevent adding text and/or placing a signature on it from Adobe Reader. To fill and sign this document you need to print it out"
    We have not made any changes to the files or our reader since the last time I used it to cause this to occur. Also, when I try to open an unsecured version from the original source I get the same error message. Other people can open on their computers from the original source without receiving this notification so it HAS to be something within my computer. I just don't know how to correct it. please help asI need to be able to fill in these forms.
    Oh, and I am using a PC with Windows 7.

    Hi Marissa,
    All you need to is give the PDF reader rights. In Acrobat 11, go to File – Save as – Reader Extended PDF – Enable More tools (Form fill in/ Sign).Hope this helps?
    Regards,
    Rave

  • Help with security updates

    Hello,
    I am attempting to get my pc to pass a Belarc test, However, It will not pass due to this error stating I need the following
    Adobe Flash Player security update for Flash Player 11.5.502.149 Plugin 32-bit
    My pc has the current version of 11,6,602,168 installed.
    What do I need to do, please be specific for me
    Thanks

    Thank you for your response, that is what I believe as well, however it does not rectify the below screen shot. I have to have this cleared before I can work. Clearing or fixing it is my issue.
    Can someone please help me with this?  My job is on the line.
    Hotfix Id Severity Description (click to see security bulletin)
    APSB13-05 Important  Adobe Flash Player security update for Flash Player 11.5.502.149 Plugin 32-bit 
    I also uninstalled the flash player and it shows, the below installed on my PC
      Adobe Systems, Inc. - Shockwave Flash Version 11,5,502,149
        Adobe Systems, Inc. - Shockwave Flash Version 11,6,602,168
    These tests are compiled using
    http://www.belarc.com/free_download.html
    Thank you

  • Need help with Security when running AS3 inside browser

    Hi,
    I am fairly new to flash, but a fairly experienced
    programmer.
    I have created a game that runs perfectly and communicates to
    a WinSock server over port 4000 to publish its final score to.
    Using simple XMLSocket and Send.
    When I run the game in the standalone flash player everything
    works perfectly as it should
    However when I embed in a HTML page or similar it goes wrong.
    The game works fine, but the final posting to the WinSock socket
    server fails. I have retrieved the error message.
    ioErrorHandler: [SecurityErrorEvent type="securityError"
    bubbles=false cancelable=false eventPhase=2 text="Error #2048"]
    My server is a local server to me running IIS 6. Everything
    runs fine by the standalone flash player so I know ports are clear
    and firewalls are not the problem.
    Searching around google and forums I have found out that in
    9,0,124,0 (the flash I am running) that they made some security
    enhancements, namely you need to post a crossdomain file.
    My file is sat in the wwwroot of my webserver where my flash
    swf is hosted and looks like
    <cross-domain-policy>
    <allow-access-from domain="*" secure="false"/>
    </cross-domain-policy>
    I have also tried adding the following to the 1st section of
    the swf file
    Security.loadPolicyFile("
    http://mydomainname.com/crossdomain.xml");
    I have tried all conbinations, but I cannot get the flash to
    communicate to the socket server when it inside a web browser.
    If i run it in the standalone player, everything works
    perfectly.
    Can someone help me please. I have been googling and ripping
    my hair out for ages. This is the final stage of my project and I
    am failing at the final step.
    Just to add.
    My server and testing computer are on the same domain, the
    web server is a win2003 server and my testing and coding server is
    a XP machine running IE7. They are linked by a ADSL router sharing
    the same external IP address but via DHCP addressing. Everything
    works fine for port forwarding of the winsocket port.
    Just to emphasis, I believe this setup is correct, as it all
    works fine when I run in the flash player.
    Many thanks

    I fixed it eventually.
    In flash 9.0.124.0 they now force you to have a socket XML
    server running on port 843 a server somewhere if you wish to use
    XMLSocket inside a browser.
    Nothing to do with domain or crossdomain.xml files.
    You need to also call
    Security.loadPolicyFile("xmlsocket://x.x.x.x:843") before you
    open the socket.
    to load in the XML that defines what is allowed.
    Search google for AS3 and socket server port 843 and you will
    find examples and even a simple Java based server to use.

  • Applet Help with security write permissions

    I am trying to write to a "file.txt". I keep on getting a AccessControl Exception. I tried editing the java.policy file manually and with the policytool.exe Can somebody please help me and tell me what I am doing incorrect. The applet is local on my computer. I trie all 3 of these following samples in my java.policy file and I have no luck.
    permission java.io.FilePermission "/tmp/*", "read,write";
    permission java.io.FilePermission "c:\\myApplet\\Client.class", "read,write";
    permission java.io.FilePermission "file:/c:/myApplet/Client.class", "read,write";

    I also have 4 java.policy files in 4 different locations on my system. Which one is the correct one to edit?
    C:\Program Files\Java\j2re1.4.1_03\lib\security
    C:\j2sdk1.4.1_03\jre\lib\security
    C:\Program Files\Java\j2re1.4.1_04\lib\security
    C:\Program Files\Java\j2re1.4.1_02\lib\security

  • Help with Security - please!

    I have an applet whose codebase is http://www.our_site.com:7777/web_reports/graph/sExcelWriterApplet.jar that needs to do two things normally prohibited in Java:
    Run Excel (located at C:\Program Files\Microsoft Office\Office10\excel.exe)
    Store and read a temporary file in java.io.tmpdir
    So far the only way I have been able to accomplish this is by having the following wide-open .java.policy file:
    grant {
    permission java.util.PropertyPermission "java.io.tmpdir", "read";
    permission java.io.FilePermission "${java.io.tmpdir}${/}HOTSalesQuery.xls", "read, write, delete";
    permission java.io.FilePermission "<<ALL FILES>>", "execute";
    This works but is obviously unsafe for distribution.
    Here are some things I have tried that SHOULD work but do not:
    grant codeBase "http://www.our_site.com:7777/web_reports/graph/" {
    permission java.util.PropertyPermission "java.io.tmpdir", "read";
    permission java.io.FilePermission "${java.io.tmpdir}${/}HOTSalesQuery.xls", "read, write, delete";
    permission java.io.FilePermission "<<ALL FILES>>", "execute";
    grant codeBase "http://www.our_site.com:7777/web_reports/graph/sExcelWriterApplet.jar" {
    permission java.util.PropertyPermission "java.io.tmpdir", "read";
    permission java.io.FilePermission "${java.io.tmpdir}${/}HOTSalesQuery.xls", "read, write, delete";
    permission java.io.FilePermission "<<ALL FILES>>", "execute";
    Thinking that maybe it didn�t like the port specification, I tried the following two:
    grant codeBase "http://www.our_site.com/web_reports/graph/sExcelWriterApplet.jar" {
    permission java.util.PropertyPermission "java.io.tmpdir", "read";
    permission java.io.FilePermission "${java.io.tmpdir}${/}HOTSalesQuery.xls", "read, write, delete";
    permission java.io.FilePermission "<<ALL FILES>>", "execute";
    grant codeBase "http://www.our_site.com/web_reports/graph/" {
    permission java.util.PropertyPermission "java.io.tmpdir", "read";
    permission java.io.FilePermission "${java.io.tmpdir}${/}HOTSalesQuery.xls", "read, write, delete";
    permission java.io.FilePermission "<<ALL FILES>>", "execute";
    Trying to restrict the file it�s executing rather than the codepath:
    grant {
    permission java.util.PropertyPermission "java.io.tmpdir", "read";
    permission java.io.FilePermission "${java.io.tmpdir}${/}HOTSalesQuery.xls", "read, write, delete";
    permission java.io.FilePermission "C:\\Program Files\\Microsoft Office\\Office10\\EXCEL.EXE", "execute";
    NONE of the above work. I�d be extremely grateful for any suggestions. This is a very high profile project and I need to get this working ASAP. I am using Java 2, version 1.4.2_06, if that helps.
    Strangely, the error that gets reported is the reference to the Java.io.tmpdir, though that doesn't change between the working and nonworking versions.
    Thanks in advance for any suggestions.

    The applet is signed, and though I did not include examples, I tried that too with no success. As rather a Java novice, though, it's possible I did it incorrectly; but the applet DOES pop up the familiar "Do you trust content from blabla" window, so I think I at least signed it correctly.
    Thanks for your response.

  • Help with images required

    Hi, I am a new Macbook owner. I transfered some photos from my canon camera last week. Today some of these are corrupt. I tried sending the folder to a friend yesterday using podmail. Quite a lot of my images are now corrupt, but not all. All I have done is resizing in Preview a few days ago. How do I fix my images? They are very important to me as they are of me and my girlfriend. Any help is greatly appreciated.

    First, did you erase the camera? If not, import the pictures again.
    Second, are the pictures in iphoto? If they are, then look in your iphoto library in your user/pictures folder and look at them to see if there are originals that weren't messed with or which are otherwise ok. If they aren't in iphoto, try importing them into iphoto and then looking at them again.
    If you erased the camera and the images are all indeed screwed up, then you need to look at what you mean by "corrupt." Is it that the pictures themselves are mucked or that you can't open them. If the pictures are bad, then your only option is to play with them to try to improve them and there is no magic bullet. If you can't open them, then select one, get info on it (command + I) and see what the thing is set to open with. Make sure a photo program like Preview or iPhoto is selected and not some text program or the like.

  • Need some help with security sandbox stuff asap please

    hey guys... so im trying to do a swfLoader call to a swf on a server from my actionscript on my local machine, when i do that i get the security sandbox violation error.... i tried adding a crossdomain.xml file to the server that has the following code in it
    <cross-domain-policy>
         <site-control permitted-cross-domain-policies="master-only"/>
         <allow-access-from domain="*"/>
         <allow-http-request-headers-from domain="*" headers="SOAPAction"/>
    </cross-domain-policy>
    and in my actionscript on application initialize i do
    initialize="init(); Security.loadPolicyFile('http://myServer.com/crossdomain.xml')"
    i also do
    Security.allowDomain("http://myServer.com");
    any ideas???? oh and i also went to this website http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager04a.ht ml and set the always allow trust locations to "/"
    any ideas on how i could possible fix this problem?? ive been trying to get around this problem for the last 2 days!!
    please help!!!!

    Hi,
    Please use policy file logging to check the exact error. This should shed some light on the problem.The procedure is detailed here.
    http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security_05.html
    Nishad

  • Help with this requirement

    Hi Experts,
    i have a requirement: i have a customer table and fact table with contains operations performed by that customers. In cust table, there is a column name CUST_KIND with contains the kind of customer. This value can change, so i need to construct a report that shows that changes of customer kind. To achieve this, in the report, i create a new field with EVALUATE and LAG sentences to catch the value of CUST_KIND of previous row, and i order the report by cust_id and time. I have the problem that analytic function LAG can't be used in WHERE clause... so, how can i achieve my requirement??? Please, answer it ASAP
    Thanks in advance.

    Hi friend,
    thanks for response. The fact table contains operations performed by customers. One column of that fact table is 'kind of customer', and this is the field that can change. So, One customer can change of kind from one week to other, so, one week can perform operations being one kind of customer and next week can perform operations being other kind of cust. Because of that, i need to build a report that shows that changes of kind of customer, comparing cust kind of one week with cust kind of previous week.

Maybe you are looking for

  • After changing the start and end of a song i iTunes, the change does no longer appear on my iPod, instead I get the whole song

    I use Ipod nano bought last year. I use iMac with OS X Yosemite. The problem appeared about 1-2 months ago Have reset the Ipod to no avail. If I have a song, say 8 minutes long, and want to start 1:00 and finish 4:00. That works alright with iTunes o

  • Not found - The requested URL /apex/wwv_flow.show was not found on this ser

    I have a very simple anonymous block (see below) which I am using to test an area of the database I am developing using OE and APEX. Sometimes the block works and other times it fails with the following error message------ Not found - The requested U

  • Intermedia Search...

    I have a problem searching for subclasses. I created an object with a subobject. In this subobject I store a document. As I can see from intermedia4s log files, the files has been indexed. But I can4t find it with der search-APIs or with the WebUI. W

  • Requirement for getting 'Powered By NetWeaver' certificate

    Hi, We are planning to get 'Powered By NetWeaver' certification for one of our application. We would like to know, whether the application should support the multiple database. Is this a mandatory requirement for getting 'Powered By NetWeaver' certif

  • Printing the Document

    Hi, I have raised an A/P Invoice by giving the 3 different Tax codes(ServiceCessHEcess) in one formula it has been calculted. My doubt is at the time of printing an A/P Invoice i want to view what are the taxes has given for the document. It has to d