Overload the default access right policies?

Hello,
We want to use Oracle Content Database to implement a DMS for a bank, who has complex access rights (as an example, imagine that the access rights become more restrictive after 8 PM).
Hence our question: is it possible to overload the standard access rights of Oracle Content Database with our own hand-crafted policies, e.g. provided in a stored procedure?
Thanks for any help
Pascal Sartoretti

Hi Pascal,
I understand.
I think what you wrote is enough for me to get a better understanding of what you're trying to do: each document in CDB may map to a transaction in an external banking application, each of which may imply its own security policy in some way.
You are correct -- there is no way to override the security model of CDB with another implementation.
However, you can change the security configuration for folders or documents in CDB programmatically with the CDB API. Therefore, it is possible to update a security configuration in CDB to match a security policy defined by an external application, as long as you can set up a "trigger" mechanism that is invoked when changes are made to the external application that need to be applied to CDB.
Of course, you will need to come up with a mapping from your external application's security model to CDB's model that is based on users, groups, and roles. Given that you are able to create custom roles and ad-hoc groups in CDB, this should be possible, depending on the complexity of your external application's security model.
You can also use the CDB EventHandler feature to implement a time-based custom "trigger" that can be implemented to make changes to CDB security at various intervals based on the rules you want to enforce.
I have another question about the application you are planning:
- Do you envision end-users accessing CDB directly, and using the built-in user interfaces, such as the Web GUI and ODrive?
- Or do you think it will be more likely that end-users will access the external "banking application" directly, which would have a custom user interface and specific features for banking?
In the second scenario, the banking application would use CDB "behind the scenes" to store and retrieve documents required by the banking application. (CDB would not need to have users and passwords for the end-users -- only one (or a few) "application" users that would be used to provide access to the banking application.)
- Luis

Similar Messages

  • I can't sync my iPod classic with iTunes 10 anymore. A notice comes "You don't have the adequate access rights to make modifications." What happend?

    I can't sync my iPod classic with iTunes 10 anymore. A notice comes "You don't have the adequate access rights to make modifications." What happend?

    bump

  • Could not open scratch file because the file is locked or you do not have the necessary access rights.

    could not open scratch file because the file is locked or you do not have the necessary access rights.

    It means what it says: Check your file permissions on your scratch disk.
    Mylenium

  • Distribution Point creation failed. possible cause : distribution manager does not have the sufficient access right to the computer

    Hi All,
    I had this really disturbing experience with
    SCCM 2012 SP1.
    OD : 2008r2 Enterprise 64bit 
    Possible cause: Distribution Manager does not have sufficient rights to the computer.
    Solution: Verify that the site server computer account is administrator of the computer.
    in Distmgr.log says :
    DPConnection::Disconnect: Revert to self
    SMS_DISTRIBUTION_MANAGER 5/26/2014 7:34:30 AM
    16280 (0x3F98)
    DPConnection::Connect: For ["Display=\\PNGBRANCHSERVER.xxx\"]MSWNET:["SMS_SITE=SSM"]\\PNGBRANCHSERVER.xxx\, logged-on as ssm\sccmadmin
    SMS_DISTRIBUTION_MANAGER 5/26/2014 7:34:30 AM
    16280 (0x3F98)
    DPConnection::Connect: For ["Display=\\PNGBRANCHSERVER.xxx\"]MSWNET:["SMS_SITE=SSM"]\\PNGBRANCHSERVER.x\, logged-on as ssm\sccmadmin
    SMS_DISTRIBUxxx ON_MANAGER 5/26/2014 7:34:30 AM
    16280 (0x3F98)
    Failed to find a valid drive on the distribution point ["Display=\\PNGBRANCHSERVER.xxx"]MSWNET:["SMS_SITE=SSM"]\\PNGBRANCHSERVER.ssm.com.myx
    DPConnection::Disconnect: Revert to selfxxx
    MS_DISTRIBUTION_MANAGER 5/26/2014 7:34:30 AM
    16280 (0x3F98)
    DPConnection::Disconnect: Revert to self SMS_DISTRIBUTION_MANAGER
    5/26/2014 7:34:30 AM 16280 (0x3F98)
     GetContentLibLocation() failed SMS_DISTRIBUTION_MANAGER
    5/26/2014 7:34:30 AM 16280 (0x3F98)
    Failed to get the content library path on server PNGBRANCHSERVER.  SMS_DISTRIBUTION_MANAGER
    5/26/2014 7:34:30 AM 16280 (0x3F98)
    Failed to install DP files on the remote DP. Error code = 16389
    SMS_DISTRIBUTION_MANAGER 5/26/2014 7:34:30 AM
    16280 (0x3F98)
    STATMSG: ID=2370 SEV=E LEV=M SOURCE="SMS Server" COMP="SMS_DISTRIBUTION_MANAGER" SYS=SCCMSVR. SITE=SSM PID=2660 TID=16280 GMTDATE=Sun May 25 23:34:30.428 2014 ISTR0="["Display=\\PNGBRANCHSERVER.ssm.com.my\"]MSWNET:["SMS_SITE=SSM"]\\PNGBRANCHSERVER.\"
    ISTR1="PNGBRANCHSERVER.S" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=1 AID0=404 AVAL0="["Display=\\PNGBRANCHSERVER.\"]MSWNET:["SMS_SITE=SSM"]\\PNGBRANCHSERVER.ssm.com.my\"
    SMS_DISTRIBUTION_MANAGER 5/26/2014 7:34:30 AM
    16280 (0x3F98)
    I have tried many of the solution provided unfortunately nothing positive happened.
    Appreciate your input before engaging premier support.
    Thank you

    Hi,
    NO_SMS_ON_DRIVE.SMS
    This file is used to prevent Configuration Manager from installing binaries to a volume. By default, when you install System Center 2012 Configuration Manager on a remote Site System, the SMS Site Component Manager Service installs the binaries (files and
    folders) for the Site System on the NTFS-formatted volume that contains the most free space. You may want to use an NTFS volume other than the default volume for your remote Site Systems by preventing ConfigMgr from enumerating certain NTFS volumes.
    In order to prevent CM from enumerating an NTFS volume, on the remote server you can create a text file that is named NO_SMS_ON_DRIVE.SMS and put the this file on the root folder of all NTFS volumes where you do not want to install the binaries (SMS folder)
    for the ConfigMgr components.
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • How do i change the access rights for every file in every sub-folder?

    I have an external drive that was shared between my PC and my iMac (running Snow Leopard 10.6.5).
    Some of the files created by my PC have the following access rights (privileges):
    Me: Custom
    staff: Custom
    everyone: Custom
    I want every file to have the following access rights (privileges):
    Me: Read & Write
    staff: Read & Write
    everyone: Read & Write
    I presume that I need to go into the terminal and run some command line program, but I have no idea what program or what options (or even where to look for such a program). Can someone tell me how to do this, so that every file in every sub-folder has the same access rights?

    Well, that's different. Most people do not install anything on their PC to read an HFS+ disk, so I assumed it was formatted for the PC. [See my above post|http://discussions.apple.com/thread.jspa?messageID=12843313#12843313].
    Note that it is the same as what you asked about, except with numbers instead of the letter equivalents.
    Posix permissions are for User;Group;Other (ugo) and each one can have read/write/execute permissions. Read = 4, Write = 2, and Execute = 1. So, for rwx you set 421=7.
    I try to make it safe by not typing in the file path. If you do what you posted, you will change the startup volume's permissions. The path to your external is /Volumes/ext hd mount point. If you start typing the path and accidentally hit return before finishing the full path, you could fubar something you didn't want to. So, I type the command, leave a space, and then drag the target to the Terminal window.
    You might also consider the GUI based permission changing program, [BatChmod|http://www.macchampion.com/arbysoft/BatchMod/Welcome.html].
    Message was edited by: Barney-15E

  • Acrobat X: Can you make 'open' the default option when opening sharepoint documents?

    When you open a sharepoint document with acrobat X, you get the pop-up screen asking you how you want to access the file. The option are 'check out and open', or just 'open'.
    Is it possible to make 'open' the default access methode, so that you don't have to click on the pop-up for every document?

    Hi Deedee,
    No, it's not really possible to set this default. 
    That said, there's a registry key setting you can change to disable the SharePoint integration feature though. 
    They key is:
    HKLM\SOFTWARE\Policies\Adobe\(product name)\(version)\FeatureLockdown\cSharePoint
    Summary: Disables the SharePoint integration features.
    Details:  Controlls the application's ability to detect that a file came from a Sharepoint server, disables the check-out prompt, and removes the SharePoint specific menu items. Possible values include:
    0: Disable the SharePoint integration features.
    1: Same as "null." Don't disable the SharePoint integration features.
    This may not really fit your need though.
    -David

  • Can you copy default Access Levels in 3.1?

    Hello,
    We are trying to create custom Access Levels that are slightly different than the default levels (i.e. Full Control, View, View on Demand, etc.)
    However, when we right-click on the Access Level it acts like it is copying, but it does not create the copy.  If we create a new Access Level and call it Test....we can copy that and it results in a Test(2) Access Level.
    It is like the default Access Levells cannot be copied/cloned.  Looking for confirmation one way or another that this can be done or not.
    Thanks.
    Kevin

    You should, there was a bug in 3.1, unfortunately. I did see that it was escalated. If you need this functionality ASAP then open a message with support so they can attach your case to the escalation too and you can get an update when it's released.
    If you have a 3.0 system available you can copy from there and migrate via import wizard. Not much of a work around I'm afraid... But a patch should be coming in a few months if not sooner.
    Regards,
    Tim

  • How can I monitor the active access point + data c...

    My privider (o2 Germany) requires me to use different access points (APN, proxy) on my phone (N80) depending on the type of browsing I want do do (WAP vs. "normal" access), and each of them has a "high cost trap" if I use the wrong one for the particular service.
    Very annoying - up to the point that I consider not using the phone for online access at all because I'm so scared to run into uncontrollably high fees.
    Anyways. I wonder if there is add-on software for my phone that helps me monitor my data connection, i.e.:
    * show me the currently used access point at the top of the display (yes, I know I can go into some deep menus to look it up, but that's not very helpful or even easy to use)
    * automatically disconnect when the conn is idle for a while (One of the data modes is time-based, meaning I do not want to have it open all the time by accident)
    Currently, all I can see at the top of the display is that I have a data connection at all, but that does not give me enough information to know I'm in the right mode for what I'm doing.
    Thomas

    You can force a disconnect by pressing the red/hangup key for a couple of seconds when the phone is in the standby state.
    And in menu > Tools > Settings > Connection > Packet data change the setting "Packet data conn." to "When needed" and leave the "Access point" setting there to "None".
    When you or apps on your phone are not doing any data transfer, then regardless of whether it is a WAP or "full" Internet packet data connection, you should not cumulate any charges.
    You can also move the Connection Manager app from the Tools submenu to the main menu, or even to the Active standby apps list (or the softkeys) for quicker access. No need to deep dive into menus for it then.
    And for individual apps, you can usually set the default access point to whatever is best to use for that particular app. For the browsers ("Web" and "Services") you can also make them ask you to pick the access point every time you connect.

  • Usage of default access modifier

    Some programmers don't use the default access modifier (package level). Is there a specific reason? If so, what is it? Or is it a good to use default access modifier?
    Thank you,
    Srikanth

    Some prefer to grant or limit access to an object by the interface they expose. In this case all methods are either public or private. Access is restricted based on the fact that only the appropriate code is given references of certain interface types and if code does not have the right interface, they can not access the method.
    Its a different style, but I use it myself quite a bit. This way I never am concerned over if it should be public,private, protected or default. The choice is simpler. But sometimes it can make you create interfaces for really simple things which I am not uptight enough to do...

  • Give access right to an user to an attribute.

    Hello
    here is the aci in directory server 5.2
    aci=aci: (targetattr = "veraFoonUsername || verafooninternaltelephonenumber") (version 3.0;acl "Deny access to verafoon";deny (all)(userdn != "ldap:///uid=v0000132, ou=People,o=vera.be,o=jes.vera.be || ldap:///uid=admin,ou=People,o=admin.vera.be,o=jes.vera.be");)it seems that this user v000132 doesnt have read rights to verafooninternaltelephonenumber. is it normal? the above aci says that it denies to all users exectp v000132 and admin in the domain vera.be. is that correct but does it give them the access to read?
    should I add another acl saying that I want this user v000132 to have read right or is it redundant?

    Someone feel free to correct me if I'm wrong, but I believe that the default access is 'deny'. So, unless there is a specific ACI granting someone access to a resource, then they will not be able to see it. With that in mind, there are some ACIs out of the box that grant access to just about every attribute to everyone.
    In my (limited) experience, I've found it best to avoid "deny" ACIs unless absolutely necessary as they can make your security very complicated and difficult to debug.

  • New Toshiba PC with Acrobat Reader pre-installed. I installed  Acrobat XI Standard. When opening a PDF, it opens in Reader. How do I get Standard to be the default?

    New Toshiba PC with Acrobat Reader pre-installed. I installed  Acrobat XI Standard. When opening a PDF, it opens in Reader. How do I get Standard to be the default?

    right click a pdf>click open with>tick use as default and navigate to adobe acrobat xi, if it's not listed in the 'open with' panel.

  • Problems Managing User Access Rights for Web Gallery

    Has anyone else had issues changing the user access rights for a web gallery? It seems like the access is everyone or no one. Are the user rights handled per event in the gallery? I had issues adding events to the user's view/download rights in the publish settings.
    Also, can these settings only be set when an event is first published? Attempting to change the user access rights after the event is published seems to require a re-upload of the images.
    Any thoughts?

    Problem solved.
    I had to put the following lines in the specified "0000_any_80.my.website.conf" file:
            <Directory "/Library/WebServer/subdomain.domain">
                    Options All +MultiViews -ExecCGI -Indexes -Includes
                    AllowOverride None
                    # For Password protection
                    AuthType Digest
                    AuthName "Password Protection"
                    require valid-user
                    <IfModule mod_dav.c>
                            DAV Off
                    </IfModule>
            </Directory>

  • Access Rights in Development system

    Hi,
    I would like to understand whether as a practice, access rights in development system also follow the same principle of need to know and need to do basis,
    or generally all the users having access to development system are given the same access rights?
    As only SAP support personnel or developers have the access to the system, Can the access to configuration (SPRO)  be restricted to the respective relevant modules like MM consultants will have access only to the MM module and SD will have SD module etc.
    I am also interested in understanding how the access can be restricted to the respective modules? i.e. what are the authorization objects relevant for this purpose?
    Thanks in advance for any help.
    Krishna

    >
    Krishna Mohan Unnam wrote:
    > I am also interested in understanding how the access can be restricted to the respective modules? i.e. what are the authorization objects relevant for this purpose?
    > Krishna
    The activities within the implementation mainly consists of one thing. Transaction codes. The tricky thing is to find out which transaction code to use, but... SAP have developed a smart tool where you define a project in SPRO_ADMIN and there you assign activities by selecting nodes from the IMG. This can then be inserted into a role via PFCG.
    You will find many hits that give you tips on how to work with it if you search in the forum!
    Regards
    Fredrik

  • 6120c - default access point and setting applicati...

    Does anyone know how to set the default access point on the 6120, for all apps? And how to allow apps to access the internet without asking? The default browser is ok but everything else (Opera Mini, Gmail, Google Maps etc) asks for permission, then an access point. I figured it out on my N73 but can't get it on the 6120.

    Thanks for the reply. I've looked in App Manager but the only context-sensitive stuff for each app is 'details' which is just the vendor and certificate, and 'settings' which is 'Software Installation', Online Certificate Check' and 'Default Web Address'.
    Doh! Just got it - choosing 'open' doesn't start the app, it gives me the options I need. Problem solved!

  • Default Access type is Open!

    The default Access type when uploading a file is "Open",
    which means anyone can access the file if they have the URL (or
    guess it). Surely this should be "Restricted" until you decide to
    open the file?
    Or at the very least, an option in the preferences to allow
    you the choice for the default?

    Hi ,
    Select that entire cell in the RTF template --->rightclick -->Borders and Shading --> Shading..
    there you select the color you want...that will be applied to the excel tempalte output also
    i checked its working....
    Thanks.

Maybe you are looking for

  • Mail in 10.6.3 doing double or triple spacing with single "return"

    I got a new MBP with OX 10.6.3. I've never experienced this problem with 10.5.8 on my previous laptop, and a call to Apple support has not solved it yet (either they never heard it or it's unique to me). Figured I'd ask the community. In the Mail pro

  • Screen Resolution problem in Solaris 10

    I recently installed Solaris 10 in a DELL GX260 pc. After I've changed from Xorg to Xsun, I was able to go into X-window. However, when I tried to change the resolution in the Java desktop, it shows an error message: The XServer does not support the

  • Mailbox viewing size and configuration has changed.

    Incoming Mailbox view has always appeared as nearly full screen, but recently as a reduced-size rectangle showing only four rows of new message titles above the contents of first message. I can enlarge total view size by dragging corner and re-center

  • Installing 10g R2 on WinXP SP2 NL gives ORA-19870, ORA-19612, ORA-06512...

    I'm trying to install version 10g R2 on the following configuration: ASUS K8V SE board + AMD 64 Athlon + 512Mb Ram + 160GB SATA HD + 18GB IDE HD Windows XP SP2 NL When I install 10g without creating the db then it installs without problem. If I try t

  • FYI Is the grass always greener?

    I hope this doesn't anger anybody, but I'm going to depart from our form theme. I read a thoughtful review of Lightroom on a Canon forum site and thought Aperture users might like as read. As a registered user of Raw Shooter Premium, I was upset when