User access control

We need to control access to certain application functionality in our system.
We are currently using the application users' role(s) to decide whether access is granted to for instance view products with a value greater than £100.
The role which allows access is therefore hardcoded within the application.
With an increase of users and also restricted functionality access within the database, the number of roles and its complexity is growing. We need to replace it with something else.
Does anyone have any suggestions?

This forum is meant for discussions about OTN content/site and services.
Questions about Oracle products and technologies will NOT be answered in this forum. Please post your product or technology related questions in the appropriate product or technology forums, which are monitored by Oracle product managers.
Product forums:
http://forums.oracle.com/forums/index.jsp?cat=9
Technology forums:
http://forums.oracle.com/forums/index.jsp?cat=10
As a general guideline, please first search the forum to see if your question is already answered. You will find answers for the most frequently asked questions by simply searching the forum. This will help you to find the answer right away and will save time for all of us.

Similar Messages

  • Adobe with User Access Control

    I am trying to watch videos which use Flash Player and they
    will play if I turn off my User Access Control however, as soon as
    I turn it back on, the videos will not play; I do not want to keep
    my User Access Control off - is there some solution to this? I was
    able to use flash before without turning this off but I could not
    tell you what happened other than I added Adobe Reader (registered
    version) and an update to my computer.

    quote:
    Originally posted by:
    brohdaw
    I am trying to watch videos which use Flash Player and they
    will play if I turn off my User Access Control however, as soon as
    I turn it back on, the videos will not play; I do not want to keep
    my User Access Control off - is there some solution to this? I was
    able to use flash before without turning this off but I could not
    tell you what happened other than I added Adobe Reader (registered
    version) and an update to my computer.
    Okay, I followed the steps for another posting...
    http://www.adobe.com/cfusion/webforums/forum/messageview.cfm?forumid=15&catid=194&threadid =1415087&enterthread=y
    However, this did not help the problem; I did everything
    exactly the way it appears on these instructions however, one part
    I had to do differently - where it states to place the
    reset_fp10.cmd I also received an administrator error
    message:
    eExtracting to "C:\Program Files\Windows Resource Kits\Tools\"
    Use Path: yes Overlay Files: no
    Error: Access is denied.
    Cannot create C:\Program Files\Windows Resource
    Kits\Tools\reset_fp10.cmd.
    Administrative privileges may be required
    Therefore, I saved this file to documents and then moved it
    to the C:\Program Files\Windows Resource Kits\Tools\ folder.
    Everything else followed just the way the details explained they
    would so I figured it should have worked.
    My main thing is, this is my laptop and I'm the only user so
    I should have Admin. privileges without any of this to begin with!
    I check my user settings and it is set at "Administrator
    Privileges." This is making no sense; I have had this computer
    three years and I went through this one other time but I cannot
    remember how I fixed it - this time I am being wise and saving
    everything in a note however, that's only going to help if I ever
    get this issue fixed.
    Can anyone help?
    also feel free to contact me by an alternate (but checked
    more frequently)
    [email protected]
    Thank you,
    Kerri

  • File structure and Multi-user access/control

    Hi All
    Currently evaluating RH. Our plan is to use RH HTML with RoboServer and either SourceSafe or Team Foundation for source control. We will be producing the "printed" manual (PDF) and publishing online help (hopefully html via RH server) from the single source layout
    Given that we will edit content in RH's XHTML editor, I'm not clear on when we should create new files or the granularity of multi-user access. We have 17 apps and I plan to use a master project and merging (because we need to link to related topics in other apps).
    I'm really not sure what should constitute a file in RH. First off, is access controlled at the file level?
    I want to have multiple authors editing the same manual at the same time, so do I need to break the manual into multiple small files (currently it's a single word doc)?
    If I do break it into multiple files, what's the best approach: 1 file per topic (or is this a requirement)?
    Finally, when I come to generate the PDF, will the files be combined. (i.e. can I have different page-breaks than I have in the RH project)?
    Any pointers greatly appreciated
    Regards
    Mark

    Hi,
    First off, is access controlled at the file level?
    Not sure what you mean by that. In source control, you can check in/out ever file independent. Sometimes dependent files will be automatically checked out, for instance images used in the css when you check out the style sheet.
    I want to have multiple authors editing the same manual at the same time, so do I need to break the manual into multiple small files (currently it's a single word doc)?
    That be the idea. Anyway, it's not a good idea to have an entire RoboHelp project in a single topic. You probably want to cut up your contents into the small chunck: topics.
    If I do break it into multiple files, what's the best approach: 1 file per topic (or is this a requirement)?
    In RoboHelp a topic is a HTML file. RoboHelp doesn't force you to split up content into one or more topics. If you are creating help for the web, you want the information to be organized in relatively small chunck so users can quickly scan through it.
    Finally, when I come to generate the PDF, will the files be combined. (i.e. can I have different page-breaks than I have in the RH project)?
    Not sure what you mean by page breaks. As RoboHelp creates HTML files, there are no page breaks such as in paper manuals. When you create a PDF, you combine the topics you need into a single document.
    If a PDF is required for you, you may want to consider not using RoboHelp for your sources. A PDF created by RoboHelp is useful for internal use, but it never seems to get good enough to give to customers. Personally, when a PDF version of a manual is required, I create the manual in FrameMaker and link or import the book into RoboHelp. You can also link Word documents, so you may want to play around with that before deciding whether to use Word, RoboHelp or FrameMaker for your source.
    Greet,
    Willam

  • More than 1 user access control of vi via web browser

    Hi all,
    Currently I've a vi that need to share it with other PCs using web browser (eg: IE) I've tried using Web Publishing Tools and I noticed that only 1 pc at a time can grant access control of the vi. May I know is there any methods or other 3rd party software that could possibly able to give multiple PCs to control one vi simultaneously over the net using web browser? THANKS!!!...

    Hello,
    I’m not so sure that using VNC or remote desktop to have
    multiple users control LabVIEW is really in-line with our license policy.  I suppose if you built your program into an executable
    and had the VNC users access the exe program they wouldn't really be using the development
    environment so I suppose this would be ok…
    I found a tutorial which might help.  Check out: http://zone.ni.com/devzone/conceptd.nsf/webmain/bc79065d8b2e0d0886256c590072a454.
    Hopefully this will help out for now!  Let us know if you have questions-
    Travis M
    LabVIEW R&D
    National Instruments

  • Authenticate users & Access Control

    Hi All,
    (First apologies if this is not the correct forum)
    I'm hoping someone can give me a little help or advice on
    options available to me.
    Using flex2 I have built a fairly simple flash app that
    currrently has two panels,
    panel1- this presents data in a datagrid which connects to a
    mysql4.x db via amfphp1.9.
    panel2- this presents textinput boxes and a submit button
    (data is submited via php script to the myqsl db)
    NB: All my users authenticate via LDAP (novell edirectory)
    & there are two kinds of users (Teachers & Students)
    What I want to know is:
    1- can I allow my users to login to the flash app via their
    LDAP usernames? (if so how could I do this)
    2- can I assign different rights to the users? (e.g. When a
    teacher logs in they get access to view & input data, &
    when a student logs in the ONLY have access to view data)
    NB: I work in a school so I don't have the budget to buy CF,
    FDS. I also do not want to use the userbase in the mysql db, as
    this would then require me to maintain two userbases (e.g. LDAP
    & MySQL) hence twice the workload.
    Any help or suggestions to best approach this problem would
    be greatly appreciated.
    TIA
    Danny

    that was my instinct exactly, we do have an LDAP here however this application has a max of 3 users roughly with one as a supper-user, so im not sure if its worth using the LDAP API at present
    i am tempted to build and access control page initially, however we are all new to APEX here and were a little worried about security issues mainly because of the nature of the information we are holding this time.
    thanks for your thoughts on the matter
    Sol

  • User access control and WebStart

    I'm considering tools and utils for a new project and WebStart looks like it could suit our needs just perfect.
    Just one little question:
    If I have a system with multiple applications controlled by WebStart, is it possible to restrict user access?
    I need to be able to present different selections of applications to different types of users, is this possible to configure/code for WebStart?
    Thankful for pointers

    At what point do you want to treat different users
    differently (like allowing access to different apps)?
    Possible points could be:
    - at the webserver level (different download pages,
    that are access protected)
    - different Web Start application caches (as far
    as I understand under Win32 all users share
    one cache - but this seems subject to some
    property configuration in WebStart)
    - within the application (the app expecting different
    license keys, passwords or such)
    - within Web Start (Web Start utility asks for password,
    this could be achieved by writing a custom jnlp
    client - think openjnlp as example
    http://openjnlp.nanode.org/)
    I think the first two options are not useful, as
    users might get the application somewhere else
    and just copy it onto their box - this is also
    true for the last option.
    So I would put access control into the applications
    themselves.

  • Multi-user access control

    User #1 opens a PDF on a server and starts making changes.  User #2 opens the same file and starts making changes.  User #2 for example can create sticky notes and make lots of comments.  When User #2 tries to save his changes he's denied as User #1 opened the file first.  Is there a way (like with MS office) that User #2 will be warned when opening the file that his version is read-only?
    Thanks!

    Sorry, no.
    Acrobat/Reader do not have their own file locking system (as Office does), so they have no idea that another user is accessing the document until they send the operating system a 'save' instruction, and get an error saying it's not allowed.

  • How do we check user access control in Apex

    Hi All,
    In my application we have three different roles like
    1 = Write/Edit
    2 = Write/Edit/Export
    3 = View Only
    Based on the roles i have dsiplay the show and hide few things. How do achieve this property in apex?
    Thanks,
    Anoo..

    Always include the following information when asking a question
    Full APEX version
    Full DB/version/edition/host OS
    Web server architecture (EPG, OHS or APEX listener/host OS)
    Browser(s) and version(s) used
    Theme
    Template(s)
    Region/item type(s)
    And always search on oracle documentation and apex forum before posting a question
    Anoo wrote:
    Hi All,
    In my application we have three different roles like
    1 = Write/Edit
    2 = Write/Edit/Export
    3 = View Only
    Based on the roles i have dsiplay the show and hide few things. How do achieve this property in apex?
    Thanks,
    Anoo..You can create 3 different authorizations for each one above, and use the authorization in the region,page, item level etc..
    http://docs.oracle.com/cd/E23903_01/doc/doc.41/e21674/sec_authorization.htm#HTMDB25782

  • Create user menus in hierarical tree with access control

    Hi All,
    I am facing problem in populating user menus in hirarical against user access control.
    I have table of menus in which i populate data as:
    Menu
    - Sub Menu 1
    -- Form 1
    -- Form 2
    -- Form 3
    - Sub Menu 2
    -- Form 4
    -- Form 5
    -- Form 6
    Now I have created hierarical query as:
    SELECT -1, LEVEL, menu_name, NULL, id
    FROM menu_opt
    START WITH parent_id IS NULL
    CONNECT BY PRIOR menu_id = parent_id
    and menu_id in
    (3, 4);
    Note: where menu_id 3 = Form 1, Menu_id 4 = Form 2.
    If I allow only menu ID 3 and 4 (not parents menus) then Hierarchy should be completed from top to bottom. What change i have to made to achieve my target?
    Thankx
    Qasim Javaid

    Hi,
    Sorry, it's very unclear what you want to do.
    Whenever you have a problem, please post CREATE TABLE and INSERT statements for a little sample data, and the results you want from that sample data.
    Say which version of Oracle you're using, e.g. 11.2.0.2.0. This is always important, but especially so with CONNECT BY queries, because every version since Oracle 7 has had significant improvements in this area.
    See the forum FAQ {message:id=9360002}
    If you can show the problem using commonly available tables (such as scott.emp or hr.employees, both of which contain trees) then you don't need to post any sample data; just the results you want and an explanation of how you get those results.
    For example, I think you're asking something like this:
    "I want to show the hierarchy in scott.emp, but I only want to show certain nodes and their descendants. For example, if I ask for 'MILLER' and 'SCOTT', I would want to see
    {code}
    ` EMPNO ENAME
    7876 ADAMS
    7788 SCOTT
    7934 MILLER
    {code}
    (order doesn't matter). ADAMS is included because ADAMS is a child of SCOTT."
    Here's one way to do that:
    SELECT DISTINCT
         empno, ename
    FROM     scott.emp
    START WITH     ename     IN ('MILLER', 'SCOTT')
    CONNECT BY     mgr     = PRIOR empno
    ;This query should work in any version of Oracle.

  • User 'Levent2-PC\Levent2' does not have required permissions. Verify that sufficient permissions have been granted and Windows User Account Control (UAC) restrictions have been addressed.

    I have run Report Manager which show the below error
    and
    web url show below error
       What should I do for solve this error?
        Plz give replay quicKly 

    Hi tusharshinde,
    Based on my understanding, you come across an issue when you try to access report manager and report server.
    In Reporting Service, after installing a new report server, only users who are members of the Local Administrators group have permissions to access report server. If we want to grant permissions for other users to access report server, we should add users
    to an item-level role and system-level role. Please refer to this article:
    Grant User Access to a Report Server (Report Manager).
    According to the screenshots, it’s clear that you don’t have sufficient permission to access report manager and report server. So in this scenario, please make sure you are members of local administrators group. To fix the issue, you could run IE browser
    as administrator  and add your account to an proper item level role and system-level role. If issue persists, please temporarily change the User Access Control settings to “Never notify”. For more information, please refer to articles below:
    SQL Server Reporting Services Report Manager Site Permissions Error After Installation
    rsAccessedDenied - Reporting Services Error
    If you have any question, please feel free to ask.
    Best regards,
    Qiuyun Yu

  • User account control won't let access to hp mediasmart photo

    user account control won't let  access to mediasmart photo.

    Thank you for the additional information.
    Here are all of the MediaSmart Software downloads provided by Daniel Potyrala:
    Hi,
    Below you will find the latest versions of MediaSmart applications:
    MediaSmart SmartMenu here (version 3.1.2.2  for 32-bit & 64-bit Windows 7)
    MediaSmart DVD here (version 4.2.5122  for 32-bit & 64-bit Windows 7)
    MediaSmart Webcam here (version 4.2.3303  for 32-bit & 64-bit Windows 7)
    MediaSmart Music here (version 4.2.4604 for 32-bit & 64-bit Windows 7)
    MediaSmart Video here (version 4.1.4322  for 32-bit & 64-bit Windows 7)
    MediaSmart Photo here (version 4.1.4327  for 32-bit & 64-bit Windows 7)
    MediaSmart DVD Menu Pack here (version 4.1.4121  for 32-bit & 64-bit Windows 7)
    You should reinstall MediaSmart Photo (second from the bottom) to see if that helps.
    Please click the "Thumbs Up+ button" if I have helped you and click "Accept as Solution" if your problem is solved.
    Signature:
    HP TouchPad - 1.2 GHz; 1 GB memory; 32 GB storage; WebOS/CyanogenMod 11(Kit Kat)
    HP 10 Plus; Android-Kit Kat; 1.0 GHz Allwinner A31 ARM Cortex A7 Quad Core Processor ; 2GB RAM Memory Long: 2 GB DDR3L SDRAM (1600MHz); 16GB disable eMMC 16GB v4.51
    HP Omen; i7-4710QH; 8 GB memory; 256 GB San Disk SSD; Win 8.1
    HP Photosmart 7520 AIO
    ++++++++++++++++++
    **Click the Thumbs Up+ to say 'Thanks' and the 'Accept as Solution' if I have solved your problem.**
    Intelligence is God given; Wisdom is the sum of our mistakes!
    I am not an HP employee.

  • Allow a user access to start and stop a particular service in Solaris 11 using RBAC controls

    So, using svcbundle I created a service called "oracle" that starts and shutdown a db. I'm aware of how to grant RBAC access to be a "service operator" to be able to control start/stop ALL services. But I'd like to grant a user access to start and stop JUST this service.
    in this document on page 15, it states that it's possible to do this kind of granularity but doesn't explain how to do it step by step.
    how does one achieve this?
    thanks.

    You need to add a property group such as
    <property_group name='general' type='framework'>
      <!-- to start stop oracle -->
      <propval name='action_authorization' type='astring'
      value='solaris.smf.manage.oracle' />
    </property_group>
    Then add the solaris.smf.manage.oracle authorization to the user profile.
    As an example, see Less known Solaris features: RBAC and Privileges - Part 2: Role based access control - c0t0d0s0.org

  • HR User, REST example - network access denied by access control list (ACL)

    Hi,
    I am new to APEX and am running the 'Oracle Developer Days' vm. I'm logged into APEX as the default HR/oracle account and I've been following the 'Creating and Using a RESTful Web Service in Application Express 4.2' training video, however when I try to retrieve information by entering a dept no. and clicking submit I get:
    ORA-29273: HTTP request failed ORA-06512: at "SYS.UTL_HTTP", line 1130 ORA-24247: network access denied by access control list (ACL)
    I've seen the following thread:
    ORA-24247: network access denied by access control list (ACL)error-UTL_HTTP
    and I've tried running the command:
    GRANT EXECUTE ON SYS.UTL_HTTP TO HR;
    but I'm not getting anywhere, presumably the HR user does not have permissions to access 'http://localhost:8888/apex/hr/employee_test'
    Any help much appreciated, also if this is the wrong forum for this question please let me know.
    Many Thanks

    Hi,
    Thank you for the link; I executed the first block of code to 'grant connect privileges to any host for the APEX_040200 database user' that did not work so I changed the user to HR within the code and re-executed and that seems to have done the trick. I guess the HR user is now in the power_users list/group?
    Thanks again!

  • Access control for different user groups in APEX 4.0

    Hi guys,
    in Apex 4.0, is there any way to use the access control page to configure access control for different user groups?
    The access control page currently only has an access control list by users with 3 privileges namely, Administrator, Edit & View where Administrator has the highest access level & View the lowest. Therefore 1 user cannot have more than 1 different privilege, however if the user belongs to 2 or more different groups then we can control what access he can have in a more fine grained manner. We also want to have more than the 3 privileges given.
    Can we assign different groups to different users and let them have different privileges to be configured by page, region, process or item level?
    Now Apex will create 2 tables, Apex_Access_Control & Apex_Access_Setup to store the application access control mode & access control list. It will also create 3 authorization schemes "access control - administrator", "access control - edit" & "access control - view" based on the 2 tables.
    Does this mean we have to change the table structures & edit the authorization schemes to suit our usage? We are reluctant to do this because if we upgrade to a newer version of Apex then we would have to merge our pl/sql coding with Apex's updated code.
    How can we auto-configure more than the 3 authorization schemes in the access control page? Is there any way to achieve a finer grain of access control based on the current access control administration page given by Apex without writing it ourselves?
    We are afraid that we may have missed something on Apex access control & do not want to reinvent the wheel.

    Hi Errol,
    to build your own application authorization scheme around the security model supplied by Apex for administration of the Apex environment would be a bad idea.
    This was never intended for authorization scheme management in custom built Apex applications, it was solely intended to control access in the Apex environment overall. The API for it is not published, and making changes to it, such as adding more roles, would run the risk of breaking the overall Apex security model. It would not be supported by Oracle and Oracle would not guarantee the upwards compatibility of any changes you make in future versions of Apex.
    In short, you should follow Tyson's advice and build your own structure. As he indicated, there are plenty of examples around and provided your requirements are not too complicated, it will be relatively simple.
    Regards
    Andre

  • User management and Access Control in HCM Cloud

    Hello,
    Information is scarce about User management and Access Control in Oracle Cloud generally. Today, I have two questions :
    - How can I bridge HCM Cloud user store with my on-premise IDM or security repository in order to allow identty governance to flow to HCM Cloud service ?
    The only information I got was that you can declare manually and by bulk import through files my users. This is not really interresting as I have an automatic IDM with workflows and identity control on provisioning and de-provisioning.
    Is there a SPML or proprietary endpoint to do it automatically ? What are the prerequisites ? Do I have to implement OIM on my side ?
    - Once my users are created, how can I do webSSO from my internal security repositories to the HCM Cloud service ?
    I do not want to distribute new set of login / passwords to my users. Is it possible to do Identity Federation (SAML 2.0 or WS-Fed) with HCM Cloud service ? What are the prerequisites ? Do I have to implement OAM on my side ?
    I accept all pieces of information you can give me on this topic to help me understand the funcitonalites, limits and options offered by Oracle Cloud and more precisely by HCM Cloud service.
    Best regards,

    OIDDAS has limited capability of access control and information hiding. Presently, the permissions and privileges can be set at a realm level, and fine grained access control / information hiding cannot be done.
    At present, the only way to restrict view and access control is by appplying ACLs (which is not the safest bet).

Maybe you are looking for

  • Navigatetourl won't open in same window and in infinite refresh

    I have a project that requires a skip button and to go to a specified url in the same window once the animation is complete. The button works, however the navigatetourl in the last frame is not behaving. Here is the code I've placed in the last frame

  • How can I save all my text messages and transfer to new iPhone?

    I'm getting a new iphone but I want all my text from my old iphone to transfer to new iphone. How can I do that?

  • Ipod doesn't work after updating software!!!!!!!

    I've just updated my ipod nano's software and it stopped working. The itunes works alright, it updates the songs and everything but the ipod itself has no image whatsoever! How can I solve this?

  • PSA SE and PS Elements 5.0 Sharing the Same Catalog

    Is it possible to set up PSA SE and PS Elements 5.0 to share the same catalog? I really like PSA SE for a nice viewer that add the cataloging aspects. The PS Elements Organizer is nice, but takes too long to load, is too big in memory, etc. I have fo

  • Tomcat doesn't update my changes

    Hi, I am using Tomcat 5.0.27 with struts. But when do any changes in any file of my project Tomcat doesn't update those immediately. For each modification I have to restart my Tomcat server, which is painful and time consuming while developing. Can a