How to menage user permission

Hi all!
I'm developing a WEB application for menaging the information on the inside of an industry.
I use struts and JSF.
The problem is that I've different type of user that can connect to the server. (sell manager, engeneer, custumer, segretary...)
Every kind of user must have a diffrent level of access.
Example:the secretary can't access in the "engeneer" zone.
Another problem is:
for the same page,the user must see a different level of details.
Example:in the production page,the engeneer must see all the data,the chemical analist must see only the chemical analisis,and so on...
how can I structure the DB for managing that?
And how can I implement it?
What do you think about creating a level between the DAO to data and the application.
Every data have a specific permission to be see.
When a request for see the data comes,I match the required permission with the user permission.
If the user can't access to data, I throw an exception,that is catch above.
Anybody knows of any kind of articles on this argument?
Any advice?
sorry for my english.

Can I revoke this permissions once I grant?
You can use DROP and REVOKE commands to do the opposite.
USE [msdb]
GO
ALTER ROLE [SQLAgentOperatorRole] DROP MEMBER [TestLogin1]
GO
USE [msdb]
GO
ALTER ROLE [SQLAgentReaderRole] DROP MEMBER [TestLogin1]
GO
USE [msdb]
GO
ALTER ROLE [SQLAgentUserRole] DROP MEMBER [TestLogin1]
GO
use [master]
GO
REVOKE ALTER ANY CREDENTIAL TO [TestLogin1] AS [sa]
GO
Cheers,
Vaibhav Chaudhari
[MCTS],
[MCP]

Similar Messages

  • How to grant user permission to create "Credential" and "Proxies"

    Hi Team,
    Kindly let me know how to grant permission for user to create "Credential" and "Proxies" on server:
    Thanks in advance
    Santosh

    Can I revoke this permissions once I grant?
    You can use DROP and REVOKE commands to do the opposite.
    USE [msdb]
    GO
    ALTER ROLE [SQLAgentOperatorRole] DROP MEMBER [TestLogin1]
    GO
    USE [msdb]
    GO
    ALTER ROLE [SQLAgentReaderRole] DROP MEMBER [TestLogin1]
    GO
    USE [msdb]
    GO
    ALTER ROLE [SQLAgentUserRole] DROP MEMBER [TestLogin1]
    GO
    use [master]
    GO
    REVOKE ALTER ANY CREDENTIAL TO [TestLogin1] AS [sa]
    GO
    Cheers,
    Vaibhav Chaudhari
    [MCTS],
    [MCP]

  • Check user permission level using jquery/javascript

    On a sharepoint page I need to check permission level for a user and based on permission level he is having i need to hide few elements on that page.any pointers on how to check user permission level using jquery/javascript.
    for eg: i need to do something like this
    if(userpermissionlevel=="custom read"){//hide some elements}
    Any pointers will be helpful.

    Try below
    function checkifUserHasEditPermissions()
    context = new SP.ClientContext.get_current();
    web = context.get_web();
    this._currentUser = web.get_currentUser();
    context.load(this._currentUser);
    context.load(web,'EffectiveBasePermissions');
    context.executeQueryAsync(Function.createDelegate(this, this.onSuccessMethod), Function.createDelegate(this, this.onFailureMethod));
    function onSuccessMethod(sender, args)
    if (web.get_effectiveBasePermissions().has(SP.PermissionKind.editListItems))
    //User Has Edit Permissions
    http://social.technet.microsoft.com/Forums/sharepoint/en-US/f21ad6b1-445a-497d-a286-d3ba8c2928a6/how-to-get-the-current-user-permission-level-on-a-list-item-with-ecmascript
    or
    http://stackoverflow.com/questions/22122139/check-if-current-users-belongs-to-sp-group-using-javascript-client-side-object-m
    http://blog.fidelityfactory.com/2011/11/29/sharepoint-client-ecma-script-check-user-permissions/

  • How to set End User Permission to an iView?

    Hi experts,
    can someone tell me how I can set End User Permission to enabled to an iView?

    Hi there,
    From what I have read you want a user to access an iView without an account. To do this you need to configure the J2EE engine for an anonymous user access and set the iView property for authentication to anonymous.
    Because the user has no account you have to assign any roles you want to use for permissions to the anonymous user account configured for anonymous access.
    There is documentation on help.sap.com on how to configure anonymous access.
    Hope this helps.
    Regards
    Christiaan

  • How to provide an exchange user permission for Mailbox Archieve ??

    i want to grant a IT guy access to archive mailboxes. How to provide an exchange user permission for Mailbox Archive ??.
    Regards, h9ck3r.

    Hi,
    Per my known, if you want to access other user's personal archive mailbox, you need to assign full access permissions to primary mailbox first.
    There is no way to grant full access permissions to archive mailbox only.
    Best regards,
    Belinda Ma
    TechNet Community Support

  • How to give an user permission to access centain Transformations?

    I would like to know how to give an user permission to access centain Transformations in one InfoArea only. I already limited the selection in one InfoArea now. I want users can only Display Transformations for all the InfoObjects under this InfoArea. Does anyone know the detail steps? Thanks!

    HI,
    are you working under Analysis Auth (BI7) or Reporting Auth (BW 3.X)?
    If you work with the new concept you can restrict your authorization by using theinfoobjet: 0TCAIFAREA.
    before you Add 0TCAIFAREA as an external hierarchy characteristic to 0INFOPROV also when you restrict your auth by infoprovider you can choose the infoarea hierarchy
    hope it help
    Regard's

  • How do I manually delete iTunes when I want to re-install the latest program? Error says I have no permission so how can I get permission?

    How do I manually delete iTunes and all its bits prior to re-installing the version 11 when I get a message saying I don't have permission.
    I am the sole owner of my p.c. and nobody else uses it. How do I "get permission" from my own p.c.?
    The p.c. is a Dell Vostro running windows 7 (64 bit) After giving up and exiting iTunes there was an error notification saying msvcr 80 is missing from your computer...Also, when I went (blindly) to administrators etc there was a red question mark against a gobbledegook long line apart from David pc which is me. Would this be some malevelant thing? Help!

    Hi David,
    Open the start menu, then select Control Panel in the right hand column. Open the Programs and Features section, type Apple in the search box at top right. You need to uninstall the components in the order suggested in the user tip.
    Once all have been uninstalled reboot and use Windows Explorer to locate the named folders and delete them. Then reinstall.
    tt2

  • How do I setup permission to transfer files to the MacMini Server. I thought I had it setup to do such but apparently not as I get an error message?

    How do I setup permission to transfer files to the MacMini Server. I thought I had it setup to do such but apparently not as I get an error message that I don't have permission?

    Both the Mac and Windows units we are usinghave connectivity to the MacMiniServer (on the same network) to open and edit files but cannot transfer new files to the MacMini. FileSharing is on. I went to File Sharing on the MacMini and added the appropriate users and checked FileSharing. Is there something else I needed to do?

  • Limited-access user permission lockdown mode and allowing anon users to view list items

    I'm working on setting up a public-facing SharePoint website that will need to support anonymous user access. I'm using the Enterprise Publishing Portal site collection template, so the Limited-access user permission lockdown mode feature is turned on.
    Everything is working great, except allowing users to view a list item. One of the key features I was hoping to leverage was the ability to display custom lists on a web page using a List View web part. Then they could click on an item and see the DispForm.aspx
    so the item's content was accessible, including any file attachments.
    A real-world example is adding an RSS viewer web part to the home page and allowing anon users to click on one of the events to see the details of it. Currently, in lockdown mode, the users gets an authentication prompt. 
    I toyed with the idea of turning the lockdown feature off. However, I'm uncertain of the full impact that would have on security. For example, I know it will allow anonymous users to see who created and modified an item, which we don't want exposed to the
    public (i.e. our employee names). Seems like opening a can of worms by disabling the lockdown mode... 
    Any ideas on how to tackle this would be greatly appreciated.

    So far, this is the most promising solution I've come across:
    http://soerennielsen.wordpress.com/2012/05/29/how-to-make-list-items-visible-to-anonymous-users-in-search

  • Don't display team in a team project based on user permission

    Hi all,
    I have a problem because I want to disable display and access to a Team Project\Team in WebAccess.
    My organization for a team project in my collection:
    Team project Customer
    --> Customer dev team (default team)
    --> Customer consulting team 
    --> Customer Support team
    Each team have an area.
    "Support team" doesn't have access to see and edit WorkItems in "Customer dev" and "Customer Consulting" areas, it's ok but I want that Support team member never have access to the "Customer dev team" and "Customer
    consulting team"
    I log in as a Support team member, Security works well for workitems but when i go to "Browse all", the popup "Browse Server" display all teams under team project name. It's a problem for me.
    Do you already see this security problem ?
    Is this possible to do this in TFS 2013 (Update 4) ?
    Thanks.

    Thanks for your reply.
    I do this test with two users : Me and ISupport (ISupport is a local account on TFS Server because I don't have permission to add user to AD for my test)
    Team Project Customer teams :
    --> Support Team users:
     - ISupport
    --> Customer dev team :
     - Me
    --> Consulting dev team
     - Me
    ISupport in only include in Team Project Customer\Support Team
    If I log in as ISupport user, I see all teams in Team Project Customer List in Browse Server popup.
    I always have an access to Customer dev team and Customer consulting team home page.
    (I can't create a bug because workitem security is set on Area permission)
    If I just remove ISupport user from Team Project Customer\Support Team, I can't see the Team project Customer in Browse server pop up, it's ok.
    How I can set permission to only limit ISuppport user to access Support team ?

  • How to give same permission from SP2010 to 2013

    Hi,
    Please let me know,how to give same permission from SP2010 to SP2013.
    because i am getting page not found error to all user who has permission in sp2010.
    Thanks

    then check this thread it has the same issue and proposed resolution
    https://social.technet.microsoft.com/Forums/office/en-US/04a5dcc0-83f8-4b44-b84c-134922902010/migration-from-sp-2010-to-2013-user-permissions-not-working?forum=sharepointadmin
    Kind Regards,
    John Naguib
    Senior Consultant
    John Naguib Blog
    John Naguib Twitter
    Please remember to mark this as answered if it helped you

  • Checking user permission doubt

    Hi everyone,
    I have posted a question yesterday, but I have no right answer. I want to try again, please help me. It is urgent! I thank in advance.
    I am developing a recursive tree in a Web Dynpro App. My tree has some nodes and sub nodes. Under the sub nodes I have documents. These documents are composed of header, footer, address, content and so on, which are loaded in runtime from Backend system. There is possible that thousand documents can be attached to a node. For accessing the documents we need to check the permission of the user. There are users who may read the whole content of a document. There are users who may only read parts of the document. For example, the information about salary of an employee shouldn't be read by every user. How can I check the user permission? Has someone any Suggestion?
    Regards,
    Hairong

    Hi William,
    thank you very much for your answer.
    I haven't worked with ACL. With your answer, I hava read something about ACL. It is used for checking user permissions for accessing portal content.We have no portal now. Our application is standalone application. Do you know what is a connection between reqular UME permission and UME ACL permission?
    By the way, we use UME to store our user profile. We have already tried to check user permission only for UME role of the user. We have also tried to follow the concept like the Web Dynpro tutorial RentCar APP with Actions and permissions. But all these can't resolve our problem really, because we can't create for every document a role or a permisson.
    here, ich want also to thank Atul who had me an answer to my question.
    Best regards,
    Hairong

  • How to control the permission for reports in share folder?

    Hi Experts,
    In OBIEE 11.1.1.6.0.
    I have created two folders in share folder,one is sales folder which contains some sales reports,and the other is dashboard folder which contains some dashboard pages that have these sales reports.
    So I want to new users who do not access the sales folder, but can view the sales reports in dashboard pages.
    How to control the permission for reports in share folder? Thanks for your help.
    Note: Dashboard pages have whole sales reports for showing.

    Hi User,
    1. Give access to the users for all reports.
    2. Give No Access to Retail Folder
    3. GIve read or full access to dashboard folder.
    To set the permission , click on the object/folder bottom left you will find Permission. you set there.
    Mark if correct,
    fiaz

  • Administrator and End user Permission

    Hello Everybody,
    How <b>Administrator permission</b> is different from <b>End user permission</b>, i cannot see any major changes if i assign or revoke those.
    2. If i have assigned <b>role assigner permission</b> to a user who does not User administrator or any other administrator rights, how he is able to assign role to other user.
    I have read on help.sap.com, but unable to understand.
    regards
    Santosh

    Hi Santhosh,
    1. The Name itself tells us the Difference .
        "Administrator" ->
           There r 3 types of Admn here
        a) "Content Admn" ( he is the one Who can create Iview / Role ..)
        b) "User Admn" ( he is the one who can Create Users and Assign Roles to the Users)
        c) "System Admn" ( he can change the System Properties ..Like Layout ,sys alias etc )
    and End User is the one who doesn't have any of the Admn Roles . A default user may contain Only EU_ROLE
    2.
       If u r a developer u must have Content Admn
       and for the basis guys must have User Admn and Sys   admn.
    Hope it helps .
    Regds,
    J

  • FPN - End user permission

    Namaste all,
    I have followed
    https://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/70191d1e-2bd1-2a10-d9b7-ba19500da527
    for setting up FPN. But I didn't understand how to assign end-user permission for a person at the consumer portal. Can somebody guide me how to search for a consumer portal user in the producer portal?
    Regards,
    Krishna Murthy

    You should just be able to navigate to User Administration tab in either portal to see the user. You can assign permissions via the PCD explorer. Locate the PCD object you wish to assign permissions to and right click and choose open --> permissions.
    This [help guide|http://help.sap.com/saphelp_nw70/helpdata/EN/f6/2604f005fd11d7b84200047582c9f7/frameset.htm] explains it in more details.
    Hope this answers your question.
    BRgds,
    Simon

Maybe you are looking for

  • I have installed itunes 10.7 and now it doesn't open. How do I get it to open?

    I have installed 10.7 on my Windows PC.  Now everytime I try and open it, it doesn't want to even open. I have looked at similar questions and try to do their solutions but to no avail. What I have tried so far: Uninstalling all the programs that hav

  • How can I turn off smooth scrolling in Lion?

    I can't not turn off smooth scrolling. Actually, I don't want to use smooth scrolling in Lion OS. How can I turn off smooth scrolling in Lion? In case of Leopard, there is option on  "System Preferences, Appearance". Please help me.

  • How long to boot MacBook pro 13" late 2011?

    It takes 1 minute 30 seconds to startup my macbook pro 13" late 2011 (2.4ghz i5 processor, 4GB RAM) This seems like a long time? I have Microsoft Office and Photoshop installed, will this slow it down? Thanks!

  • DACL format fo cisco ISE&ACS

    Hi, could anyone direct me where can I fine DACL format fo cisco ISE? Bacause when I use simple ACL like permit tcp any 10.8.26.0 0.0.0.255 eq 3389 My ASA says in log: Unable to install ACL '#ACSACL#-IP-standart_vpn-50fa79e7', downloaded for user kra

  • Why do I get  a java.lang.OutOfMemory exception

    Thanks, in advance, for you help. I just wrote a fairly large program. Every time I run it, I get a java.lang.OutOfMemory exception. I have no idea how to debug my code. Why would I get such an exception and how would I debug it?