Some privileges granted to role not being inherited by users

I have created a role(app1_role) for a group of users and granted a select number of privileges to app1_role and then granted the app1_role to the users. However some of the privileges are not being inherited by the users in the application. The failures are in the plain sql code NOT in the PL/SQL code. The Oracle version is 10.2 on RedHat zLinux.
Any insight to why we are seeing this problem would be helpful since I do not want to explicitly grant the privileges to each of the users.

Can you get the results of querying SESSION_ROLES and SESSION_PRIVS in a session where you are getting the ORA-00942 errors?
Do your SQL statements include explicit schema names? Or do they rely on synonyms? Public or private synonyms? If you rely on private synonyms, any chance certain users are missing certain synonyms?
If you query DBA_ROLE_PRIVS for the user (GRANTEE) and role (GRANTED_ROLE), what is the value of DEFAULT_ROLE? Any chance the role was granted as a non-default role?
Have you verified that in the particular installation that is problematic that the role actually has the grants you expect it to have and that it has been granted to the user(s) you expect it to be granted to?
Justin

Similar Messages

  • Privileges granted to roles sometimes are not effective(not functioning)?

    Hello,
    I have experienced where roles where granted and privileges granted to the roles. The roles are they granted to certain users. But when these users try to perform dml/ddl, they get insufficient priviledges even though these users were granted the roles which do contain the correct priviledges. Why are some priviledges not functioning when they are granted to the roles? To resolve, direct grants were granted to the users. But why aren't they working through the roles? Thank you.

    Hi watson2000 ,
    can you send the scripts...what you have performed.
    Since, I did not faced any problem with granting privliges and roles.
    If you provide some information on that (little more) whjat you have done so that we can help you out..
    Thanks
    Pavan Kumar N

  • Default File Permission not being inherited from parent Share folders

    I'm having some trouble with file permissions
    on one of my 10.4.7 file servers (running XServe).
    New folders under Shared folders are not getting their
    permissions from the parent folders.
    Share permission is owner:rw,group:rw,everyone:none
    but a new folder created below that becomes
    owner:r+w,group:r,everyone:r
    and the owner for the new folder is the user who
    created it and not the admin (for the machine).
    I have the default permission to set to inherit permission
    from parent but that doesn't seem to be working.
    I have couple other Xserve 10.4.7 file servers that
    is behaving the way I want, with default permission
    is being inherited from the parent folders, and I've compared them but cannot find any difference between
    the two in their settings.
    Thank you,
    Tadashi

    If you deny read and execute access for any parent folder, you've denied the ability to access its contents. The POSIX execute bit for folders is the switch that determines whether or not the folder's contents can be viewed, listed, or searched. If the contents are not enumerable, then it doesn't matter what their privileges are.
    But be careful. Just not allowing execute for the POSIX owner, POSIX group or POSIX everyone else field may not be sufficient if you're using Effective Permissions. In this case, you'd want to inspect your ACL entries for the parent to ensure that the following controls were not in relevant ACL Allow entries: readextattr, readattr, readsecurity, list, and search. You could also create an ACL Deny entry which denies these five controls for the group or user you want to block out; but don't block the Everyone or Authenticated Users group because ACL Deny rules are evaluated in such a manner that they "subtract from" ACL Allow and POSIX permissions:
    E <=> (P U A)\D
    Effective Permissions (E) are logically equivalent to the union of (U) applicable POSIX permissions (P) and applicable ACL Allow entries (A), taking away (\) applicable ACL Deny entries (D).
    Further, POSIX permissions, P are defined as P <=> (u xor g xor o); they are either the permissions of the owner (u), group (g), or everyone else (o) fields, but not any combination of the two or three.
    --Gerrit

  • HT1473 I am attempting to import my CD's but I'm finding some songs and albums are not being accepted.  Any ideas what I'm doing wrong?

    After attempting to import music from CD's I am seeing that some of the tracks are not listed in my iTunes library and in some cases, whole albums are missing.  Any suggestions on what I am doing wrong or how to correct?

    Now that we've established that you have the CD correctly imported into iTunes, we can move on from there.
    Connect the iPod to iTunes. When it shows up as a Device (in the left window of iTunes) select it. You will be looking at the Summary tab (or pane).
    On this pane, my choice is to have the option to Sync only ticked songs and videos selected. I recommend this option for you. This is relevant to the next step.
    At the top of the pane select Music. On this pane, check the options for Syncing. You need to have Sync Music selected and then choose either Selected Playlists (which will only put your choice of Playlists onto your iPod) or Entire Music Library. If you select "Entire Music Library" then all your songs (one exception) will be transferred to your iPod.
    The exception is: if you un-tick a song in your iTunes Library, then at the next Sync, it will be removed from the iPod but kept in your Library.
    Any luck?

  • Policy not being applied to users

    I have a group policy that used to work, but now has decided it does not want to be applied to the workstations anymore. I don't know what may have happened to make is stop working.
    It's a pretty restrictive policy for students. I have the exact same policy for two other groups of students that still work. All three policies were copied from the same set of files. In other words, I make a change to one, then copy the files to the other two because they reside on different servers. Yes, I do open each one in C1 to update the timestamp.
    When I run wmsched, the policy is there in the list, but the settings are not applied. I can log in to the PC with one of the other student accounts and their policy is applied.
    The login I'm using to test with has R rights to the policy location - the same rights that the other users have to their policies. I have also tried more rights with no different results.
    The DLU part of the policy runs, and I have turned off the windows firewall. I have also created a brand new policy from scratch to rule out any corruption in the old policy and I get the same results.
    Apparantly, my workstation policy for this group is not being applied either. The other two groups' policies apply like they are supposed to. So this means that neither policy assigned to this group of students/workstations is working.
    Any ideas?
    Thanks

    FishEggStew,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Visit http://support.novell.com and search the knowledgebase and/or check all
    the other self support options and support programs available.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://forums.novell.com)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://forums.novell.com/faq.php
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://forums.novell.com/

  • "Role not defined for individual users" on user import

    Hello,
    I am trying to import a certain user from one portal to another and I get this warning message:
    "Role <pcd_role_path> not defined for individual users."
    This role is assigned to this user at the 1st portal and exists at the 2nd portal at the same location.
    What does it mean and what do I need to do in this case?

    hi Roy,
    just check one thing ....
    please check wether the user have permissions to those roles.
    please go to the PCD location, where the roles have defined.
    right click on the role and check permissions.
    see if the user you are using is mentioned there. if no, add your user with read/write end user permission.
    i hope this will help you .
    Regards,
    Sujay

  • Table privileges granted to roles [ROLE_TAB_PRIVS]

    Hello,
    i am trying to fetch all roles, table_name and privilege using table ROLE_TAB_PRIVS.
    BI went to check which roles are displayed in that table and it says:
    Information is provided only about roles to which the user has access.
    Here is my problem ... i can not find some of the roles that are 100% created ... i have tried even with sys user but still no success.
    Is there a way to query all roles created in DB with table_names & privileges?
    Thank you in advance!

    Hello,
    i can see roles i am looking for in :
    SELECT
    FROM dba_tab_privs;
    SELECT
    FROM DBA_ROLE_PRIVS;
    But still not the information i need. I want to get exactly the same data as from table ROLE_TAB_PRIVS but
    as i said i am missing a lot of roles in that table (missing as i do not see them).
    Thank you!

  • Roles not being removed from CC5.2

    After we run a full sync for users and roles we are still finding roles in CC 5.2 that have been removed/deleted from the SAP backend systems.

    HI,
    Try with a new job and for being on the safer side select all of the choices for full Sync - i.e profile, role and users. Also, select the relevant options for your system for the Batch Risk Analysis and the Management Reports too.
    Sometimes it is a common problem that Management reports show data for a role to be in Risk, which does not even exist because we did not check this option of Management reports while running the BG job.
    This might take a bit of longer time but will be accurate.
    Regards,
    Hersh.

  • Some Language specific special characters not being displayed correctly.

    Hi All,
    In one of our JSP pages, though the required charsets for the languages "FRENCH", "GERMAN" and "ITALIAN" are mentioned, weird characters are being displayed.
    Example :"actualités" is being displayed as "actualit�s".
    Regards,
    Akhil.

    Hi Anushree,
    These are umlauts, which needs to written with with their corresponding ascii code in resource properties file.
    Like é is written as \u00e9. You need to replace these umlauts with their ascii code in resource file to get the right view.
    Regards,
    Arshi

  • Permissions not being inherited to subfolders

    I have recently formatted a 1TB WD drive in Mac OS Extended (Journaled) format. The pemissions are set to read + write for all users on the root of the drive. However when i create a new folder it does not inherit the same permissions! The drive will be used by other devices other than my Mac and they need full write acced to it.
    What settings do i need to change to ensure the new subfolders inherit the root permissions.

    The easiest way to accomplish this on an external drive is to open a Finder  Info window on the drive (Get Info) and at the bottom of the window, below the listing for the permissions is a checkbox, Ignore ownership on this drive (or ignore permissions, can't remember the exact wording)
    Set that and everyone will have full access to the drive
    Message was edited by: Frank Caggiano - You could also accomplish this with ACL's but it can get a bit complicated.
    The trouble I see with using umask for this is that all files will affected not just the ones written to this particular drive. That may not be a problem but it is something to keep in mind.
    The two solutions I mentioned will only affect this drive.

  • Some of my songs are not being downloaded to my ipad

    I have 75 purchased songs from itunes and only 25 of them are able to download, any solution to this problem.

    Hi,
    Sometimes the text fields automatically get locked. please check whether the fields are locked, if so unlock the text fields.
    Hope its should work.

  • Transported Roles not Visible for the User Log-in

    I have three roles in the development system.  These roles show up in the top level navigation for the users in the dev system.  All these roles and the underlying BSPs are transported to QA successfully.  I could assign them to users without any problems, but when the users log-in they can not see any of these roles at the top level navigation (In fact, they just get a blank screen).  "Entry Point" setting and "Sort Priority" is maintained for all the three roles.
    As a test, I created a new role with the same BSP links in QA itself and assigned it to the users.  This shows up in the top level navigation for the users.  I am wondering what's wrong with the transported roles!  If someone could help me here that would be great and I will assign points to helpful replies.  I have a very basic knowledge in portal.

    After applying SP12 in the portal landscape (EP 6.0), the role transports only work in our test environment, but not in production.  Even the manual corrections suggested in OSS note 1002832 didn't help.  I can preview all the iviews in the roles with my user id (admin id), but as soon as I log-in with the end user id nothing shows up [Not even the top level navigation tabs show up].  The following is the portal authorization methodology I chose.
    1. I assign users to the user groups
    2. I assign user groups to the roles
    I want to emphasize that all is well in our test environment, it is the production environment that shows inconsistency.  Let me know if anyone has any pointers.

  • I have access to sa role not to the sa  user itself

    Hi ,
    I'm a sybase/oracle dba, I have full access of the sybase db (via the sa role),
    but I do not have access to the sa user itself.
    How can I iuse the Migration tool ?

    Cornelia
    The problem one faces is that the SDK does not access Print or Book. You'll need to (ab)use the fields that are available, and I'd suggest you look at my Search and Replace plugin which can transfer values between fields. So you could move info from an inaccessible field to one that can be printed. Maybe use virtual copies which you can just discard afterwards?
    John

  • Roles not getting assigned to User OIM11gR2

    Hi Experts,
    I have created a Role, Access policy for ACF2 and a rule for automatically provision Users whose Company Code = 200 (company code is a UDF)
    The records are getting provisioned if I assign the role manually to the user and run Evaluate user Policies task. But if i reconcile the user from trusted resource, the users with company code are not getting even the role assigned to them.
    Am i missing something. Please help me out!!

    hi,
    have you run the configuration wizard?
    http://yourhost:port/nwa/cfg-wizard
    there is a task for BPM. just execute it.
    if you have already run the wizard, you can go to following place to check and make further change if required.
    http://yourhost:port/nwa/sys-config
    select "Applications" tab
    put "bpembaseear" in the name filter, select that application in the result table
    you will see the properties tab
    if your locale is not there, you can fix now.
    Best regards,
    John

  • Online Archive Warning Alerts not being sent to Users

    We have exchange 2010 SP3 Rollup 7 and we utilized Online Archive of Mailbox. Each user has 2 GB of Archive Quota and 1.5 GB of Archive Warning Quota. Users don't receive any warning alert if they exceeds Archive Warning Quota. I suspect this is default
    behavior in Exchange 2010.
    Is there any change in this behavior in Exchange 2013 ?
    Regards, Sourabh Kumar Jha | Please mark it as an answer if it solves your problem or vote as helpful if you like it. |

    Does user receive warning message via OWA?
    Ans. - No
    How do you set the Archive Quota and Warning Quota?
    Ans. - It's
    the same way you have mentioned, We have archivequota of 2 GB and ArchiveWarningQuota of 1.8 GB.
    Generally, Warning Quota Alert works well, I find a blog on mailbox quota trouleshooting for your reference, hope it is helpful.
    Ans. - Have you seen any archive warning quota email, I don't find any sample email
    or reference for the same. Could you try to reproduce if you have any testing environment.
    Mailbox Quota in Outlook 2010 - general information and troubleshooting
    tips
    Ans. - Information
    in outlook shows correct, I'm concerned because user's do not receive alert when they exceed their archive warning quota.
    Regards, Sourabh Kumar Jha | Please mark it as an answer if it solves your problem or vote as helpful if you like it. |

Maybe you are looking for

  • PS CS6: It'd be helpful to have the option to collapse or expand the nested groups and layers.

    PS CS6: It'd be helpful to have the option to collapse or expand the nested groups and layers all at once.  Autodesk Maya has a similar feature in it's outliner that allows for you to do this.

  • Download Adobe Flash unsuccessful on Safari

    My issue is that I click on the install icon and it says it completes, but it looks like it wasn't successful because there are zero kb used.  Adobe Flash Version 16.0.0.305 on Safari Version 5.1.10 (6534.59.10) on mac.  Symptoms are that anything af

  • I upgraded to iTunes 5.0 and have lost album art??

    Hello, I haven't been around much lately since I have not had any problems. Well, my hard drive died on this Dell and I just back up and running. Lucky for me that I have a backup system on an external hard drive. I figured I would upgrade to iTunes

  • FAH Default Conversion Rate Type

    Hello all, IN FAH you can assign the system source 'Default Conversion Rate Type' to the accounting attribute 'conversion rate type'. Great! But what rate type will it pick up, where do you set this default rate type? thanks Abe

  • Can't show correctly a variable height content application

    I've an apllication with no fixed height (it loads dinamicaly content which has no fixed sizes). When I launch the application into a navigator, if object param height isn't defined then the application is clipped and if object param height is define