Is security allow users include File item?

I would like to know if there is documentation about File item and zip item security.
There is any problem to allow users include File item?
The could use it to broke or attack the system?

John, My only doubt is if I set "Read
items that were created by the user" and "Create
items and edit items that were created by the user" in the Advanced settings sections, are these 4 super users can see all the items in the list even they have Full control access?

Similar Messages

  • How to allow user upload file on applet??

    Sorry I'm new to programming here, but I'm trying to allow user to upload a file to the server so the program inside the server can user the file as input.
    I've noticed that JFileChooser, the ideal class for this, is not allowed on the applet, so I don't know how to go about doing this.
    Thanks for any input!

    ok
    you wish to transfer a file from applet to server.
    1. Applet gets the file
    the applet needs to access the file System therefor it must b a signed applet to get aound the security restrictions. This is why the JFileChooser doesn't work. Check out the tutorials on jars and applets, particularly the security notes.
    2. opens a connection with the server
    so the applet has a file and needs to send it. there needs to be a service of some form on the destination computer to execpt the file. Perhaps you write your own perhaps you use HTTP.
    3. server software stores the file
    where an applet is an mini application that runs within the confines of the web browser. a SERVLET is a service program which runs with in the confines of a server, such as a web server.
    this is a lot easier to do HTML rather that applet in my opinion but which ever.

  • Allow users to delete Items/documents that thhey have posted

    Using SharePoint 2013.
    We would like users to be able to delete items and documents that they have posted, but not anything created by another user. It would appear that delete is not so fine grained. For a list, we can use "create items and edit items that were created by
    the user" to allow them to edit, but have found nothing regarding deletion...though it may be covered by edit.
    Libraries do not seem to have this option, and I have not found a good setting in PowerShell, at the library (list), or Items level.
    Any thoughts would be most appreciated.

    oldamigauser
    Unfortunately, setting Item-Level Permissions is no longer available for document libraries in 2013, either through advanced settings or via PowerShell. It is still available for lists in 2013 - some list-types that is (it's not available for the Issue Tracking
    list type, for example).
    As far as implementing finer configuration of the delete permission, there is no OOTB way to differentiate delete permission by whether the person attempting to delete an object was the creator of that object.  It is possible to create a permission
    level that enables users to read and edit list and document items but not delete them.  To do this, you will need to create a custom permission level - probably using the existing Contribute permission level as a template.
    Something approaching your needs could be accomplished by: 1) creating a custom permissions level that includes all of your users and that enables them to do everything the Contribute permission level allows them to do except delete; and then 2) place your
    select users into the OOTB Contribute permission level which enables them to also delete items.
    References
    Configure custom permissions in SharePoint 2013

  • BEx/BW security - Allow users to only create/chage queries Y_*

    Hello Gurus,
    I am trying to allow certain users the capability to only create and change queries that start with Y_* and X_* prefix in the technical name.
    I have the following in the security role:
    S_RS_COMP:
    RSINFOAREA *
    RSINFOCUBE *
    ACTVT 01, 02, 16
    RSZCOMPID Y_, X_
    RSZCOMPTP REP
    I have tried different combinations of things, but no matter how I tried I only get 2 results, either users cannot change any query at all, or if they are allowed to change anything, they can change ANY query. Seems like Y_* and X_* restrictions on the name never work.
    Please advise.
    Thank you,
    Andrei

    Hi,
    Please check note 540720.
    540720    FAQ: Information on S_RS_COMP and S_RS_COMP1
    Also check whether the following information helps you,
    The authorization always is an OR process. If any particular user is
    having authorization for a particular activity in any one auth object,
    and the same activity restricted for him in some other auth object. The
    user will be able to do that activity as auth is there for user in one
    auth object. So even if you have defined all the activities
    (change/create etc) for all the reports in S_RS_COMP and restricting the
    activities to the user in S_RS_COMP1. So the user will be able to do all
    the activities as he has auth as per object S_RS_COMP. What you can do
    is just give display auth in S_RS_COMP and provide create/change options
    in S_RS_COMP1 with owner = $USER.
    Regards,
    Amit

  • Simple File Item

    Hi,
    I am new to portal development, and i need to add some links in a page , so that clicking the link download a file, i used a simple file item, but i need to know how to prevent the user from downloading if he is a public user and hasn'y yet logged in.
    i want to display a message " you have to login in first" or redirect him to the login page

    You can use Enable item level security,
    Page properties >> Access tab >> check the box 'Enable Item Level Security'.
    Then, Edit file item >> Access tab >> grant the required access.
    Thanks,
    Krishna

  • Include User Defined Language Items

    I am currently developing an app that needs to let users
    define their own editable text for some items.
    I didnt want to include all of these options in the database
    to avoid having a large database and lots of cfquery's so I though
    having them in a file of some sort would be best, and just
    including the file as needed.
    So, having thought that I put a bunch of cfset's in the
    language file and set all these variables, but then I realised that
    someone could put a cfdump in there and have the app spit out
    information that they shouldnt see.
    So how can you let users define language items in a file and
    load them as usable variables, but not allow them to put other CF
    tags in that page?

    Is it possible to use regex somehow to loop over a file that
    contains lines like <varname = 'what you want'> and have
    everything between the '' stored in an two dimensional array with
    the variable name as the name?
    Are there any suggestions about the best way to handle
    this?

  • How can I allow users to view any Wiki Pages inside my enterprise wiki site collection, as PDF files

    We are working on an enterprise wiki site collection, and users start adding wiki pages and link them together. But a new requirement was raised by the customer, to allow users to be able to convert any wiki page to pdf file and save the pdf file to their
    local PCs. They are suggesting to add a link or an option inside the upper ribbon , named “Make as PDF”, and once clicked they can view the current wiki as a pdf file.
    Not sure what are the capabilities of SharePoint 2013 to do so ? and is there any third paryt tools that allow doing similar tasks ?
    Thanks

    If you want to save as PDF, could you not use a PDF printer, so the procedure would be to 'Print this page' and the user then selects their PDF printer and where they want to save the file.
    but in this way the user will have the page header footer, left navigation included in the pdf file. while i want to extract the body only. i so not think you apprach will work for my requirements

  • How to allow users to include a photo when submitting a form

    Using Adobe Livecycle Designer ES Version 8.2.1.3144.1.471865
    Would anyone out there know how to add the functionality of allowing users who are filling out a form to include a photo when submitting the form?
    Thanks in advance for any help.
    Regards,
    Lola

    Hi,
    If you drag an imageField onto the page, when the user clicks on this at runtime, they will be prompted to select an image file.
    There is an example of that in this form: http://assure.ly/j1KdNq.
    There are more image field examples on our site, but I don't think any of them are set up for the user to select an image. http://assure.ly/ozrNSO.
    Hope that helps,
    Niall

  • How to secure the users from deleting the work items

    Hi all,
    I have a question like this.........whether we could secure the users from deleting the work items by someone in the Project and also assigning a specific user to allow them to delete the idoc. 
    Please help me on this as this is critical.........
    Thanks in advance
    Chakri

    One of t he possible way is, ask the basis team to create users as Service Users and you can determine whether the login user is whether a service or dialog user  by using the a bapi BAPI_USER_GET_DETAIL under the exporting parameter logondata with field USRTYP where if the logged in user is Service user then this field will be populated as S if the user is a dialog user then it will be populated as A.
    Now in more efficient way of fixing this is get the list of users for whom you donot want to give the authorization of deleting workitems and assign the appropriate role for all the listed users...
    for roles and authorizations i hope the basis team is the right team to consult....

  • Security error - User is not allowed to execute Proces - Resolved

    Enabled security on my domain by editing message-handlers.xml :
    <inbound-flow>
    <!-- <message-handler id="default" />-->
    <message-handler id="security" />
    </inbound-flow>
    commented out <property id="SecuredProcesses" > .. </property> to apply security to all processes.
    Now when I initiate process through BPELConsole I tick the WS-Security and use bpeladmin/welcome1 as credentials (I'm logged into console as this), I get the following error. In fact I get the very same error if I make up a username/password.
    <2007-10-24 08:17:41,343> <ERROR> <archi2.collaxa.cube> <BaseCubeSessionBean::lo
    gError> Error while invoking bean "delivery": [com.collaxa.cube.engine.handlers.
    HandlerInvocationException: Error while invoking inbound message handler.
    An error has occurred while attempting to invoke the inbound message handler cla
    ss "class com.collaxa.cube.security.Authenticator" for the message "". The exce
    ption reported was: User is not allowed to execute Proces, User[true] process [f
    alse]
    ORABPEL-02175
    In bpel.xml of the process itself I have this:
    <?xml version = '1.0' encoding = 'UTF-8'?>
    <BPELSuitcase>
    <BPELProcess id="SQTest2" src="SQTest2.bpel">
    <partnerLinkBindings> ....snip...
    </partnerLinkBindings>
    <preferences>
    <property name="user" encryption="plaintext">bpeladmin</property>
    <property name="pw" encryption="plaintext">welcome1</property>
    </preferences>
    </BPELProcess>
    </BPELSuitcase>
    If I don't supply username/password then I get "Could not apply security [No username provided, security expects user]" which sounds right enough.
    I'm using the default authentication scheme system-jazn-data.xml and using 10.1.3.3 patchset on linux.

    My own fault, putting user credentials in wrong place in bpel.xml:
    <?xml version = '1.0' encoding = 'UTF-8'?>
    <BPELSuitcase>
    <BPELProcess id="SQTest2" src="SQTest2.bpel">
    <partnerLinkBindings> ....
    </partnerLinkBindings>
    <configurations>
    <property name="user" encryption="plaintext">bpeladmin</property>
    <property name="pw" encryption="plaintext">welcome1</property>
    </configurations>
    </BPELProcess>
    </BPELSuitcase>

  • Set default password for all users including csv file

    I would like to set the default password for all users
    including the ones imported in the csv file?
    Also now the default passwrd in set to the email address. How
    do i change that setting to the "login" setting in the csv file so
    those users can loin with that password?
    Kinda the same question but do yuo get the idea?
    Thank you,
    Chip

    You could download and install RCDefaultApp 2.1 for all users: check the Read Me and then test it on something to see if it accomplishes what you want.
    http://www.rubicode.com/Software/RCDefaultApp/

  • Allow user to select each item in list item only once.

    Hi,
    What is the best way to go to stop the user selecting the same item in a list item more than one.
    I have a multi record block, the user can select values 1-10 for each record, but they should not be allowed to select duplicates.
    Thanks for any help!

    Hi,
    Suppose you have 4 list items A,B,C,D in block "test" and same 4 values in each list item. Now you want that, no two values selected by user in list item should be same.
    On when-validate-item of list item B write code like :
    If :test.A is null then
    Message('First A must be enter");
    Raise form_trigger_failure;
    end if;
    If :test.B = :test.A then
    Message('value already in list item A');
    Raise form_trigger_failure;
    end if;
    Now, for C same code with a addition of condition for B with OR operator like:
    If :test.C = :test.A or then :test.C = :test.B
    Like that.... you can achive your functionality.
    But one restriction is that user has to enter values in list item in a pre-defined order only....
    Hope that it would work for you.....

  • Allow user to access /edit/delete/add specific items in list

    Hi
    I have one custom list.
    every month department head is creating some activity because of which some items are getting added in that list pragmatically.
    like-
    departmentID item1
    item2
    DEPT001 item001
    item002
    DEPT001 item003
    item001
    DEPT002 item004
    item001
    After that User want to edit or delete or add new entries only related to their department only.
    How can allow user to edit/delete or add entries (full control) only related to his department in the same list?
    How can I assign users for this?
    Should I create another list having department id and user mapping?
    please suggest any soln.

    The flow is like,
    User(Dept head/department user)will select department from drop down and clik on button to add some entries against the department.
    once the entries done he just click on save button.
    after some time if department head/department user want to add/edit/delete some entries against his department then he should able to view only his deapartment entries.  
    Also the email is generated to his manager.
    So my question is how should I allow user to view his own entires only which should be available for him to add/edit/delete.?
    If I create one list of department  and on adding the entries against each department I will add departmentID for every entry so that I can filter them by department.
    but how to allow users for those entries? If I added user for each entry and if any department user changed then I have to change his name from all entries for that department.If the entries are more than 50 or 100 then it will be very difficuelt to handle.
    Also for multiple users for single department this is very difficuelt to provide access.
     is there any alternate solution for it?

  • Include Sub-Items option in User Default Books

    Hi,
    I have > 1000 users in my On Demand system and the Default Book parameter on a User is set to a Book say "Sales" instead of "Sales +"
    I want to do a data Import to set this from "Sales" to "Sales +". I tried doing an Import using the data Loader and also a Web Service.
    but Default Book is still set to "Sales".
    The + sign will include the sub-books in the search and this is what I want. the + sign will be set only when the "Include Sub-Items" is checked while selecting a Book.
    Is this something that can be done only manually? or is there a way to do it using an Import?
    I tried doing this using an Import with Default Book = "Sales +" but the import failed. even when I export the user record the value is exported as "Sales"
    Has anyone faced this before?
    Thanks,
    Royston

    hi Ram & Sreenivas
    Thanks for your immediate response.
    Ram, we can default GL a/c & cost centre in org structure since client wants to us to keep the option of entering these for every shopping cart.
    Sreenivas, I checked the 'copy to clipboard' option & its not there in EBP2 and I feel what you meant as cost centre tab is account assignment tab.
    Let me explain you more clearly about this requirement.
    Current Scenario
    1.Say a user has added 5 items to his SC.
    2.User has to enter cost centre & GL code 5 times & then he can order
    Required scenrio
    1.Say a user has added 5 items to his SC.
    2.As per the proposed functionality, user will click on 'Default settings for items' button. Three tabs will appear-->Basic data, Internal note & Delivery Address.
    We have to provide a new tab here where in user will default his GL & cost centre for this shopping cart & then order. This will help user to avoid entering GL & cost centre 5 times.
    For some reasons our client is not interested in defaulting this data.
    Please help in this regard if time permits.
    Thanks
    Raghu

  • Don't know how or where to create user.js file so I can add script to allow copy and paste into a webbased email

    I am trying to compose an email from the email address on my web page. The email editor program (or Mozilla) doesn't allow me to do that. The instructions that Mozilla provided said to find the user.js file in Firefox's profile directory. I can't find such a file. I don't know where or how to create this file or how to write into it the lines that the instructions provided. I also don't know what url I am supposed to substitute for mozila.org that is in the lines of script.

    This was helpful. Now, to to do what I need to do I have to add something to the user.js file as per directions regarding ''setting prefs for Mozilla Rich Text Editing Demo'' to allow a copy and paste. It instructs me to change the URL from mozila.org to where I want to enable the function. I am not sure what that means. I am trying to to do something in the "back office" of my web site. I want to send an email from the web site's email. I am trying to copy and paste a pdf file into the body of the email but was not able to do it. I was directed to the setting prefs page. Do I change the location to the URL of my web site or the web site of the web host?

Maybe you are looking for