<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Oracle Designer &#8211; Script for verifying the privileges assigned to roles against the Module Table Usages</title>
	<atom:link href="http://technology.amis.nl/2005/11/23/oracle-designer-script-for-verifying-the-privileges-assigned-to-roles-against-the-module-table-usages/feed/" rel="self" type="application/rss+xml" />
	<link>http://technology.amis.nl/2005/11/23/oracle-designer-script-for-verifying-the-privileges-assigned-to-roles-against-the-module-table-usages/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=oracle-designer-script-for-verifying-the-privileges-assigned-to-roles-against-the-module-table-usages</link>
	<description></description>
	<lastBuildDate>Fri, 12 Apr 2013 10:04:09 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Lucas Jellema</title>
		<link>http://technology.amis.nl/2005/11/23/oracle-designer-script-for-verifying-the-privileges-assigned-to-roles-against-the-module-table-usages/#comment-2611</link>
		<dc:creator>Lucas Jellema</dc:creator>
		<pubDate>Tue, 24 Jan 2006 16:25:04 +0000</pubDate>
		<guid isPermaLink="false">http://technology.amis.nl/blog/?p=910#comment-2611</guid>
		<description><![CDATA[Victor,

I have tried to provide help in a new post. See &lt;a&gt;http://technology.amis.nl/blog/?p=1023&lt;/a&gt;]]></description>
		<content:encoded><![CDATA[<p>Victor,</p>
<p>I have tried to provide help in a new post. See <a>http://technology.amis.nl/blog/?p=1023</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Victor Bax</title>
		<link>http://technology.amis.nl/2005/11/23/oracle-designer-script-for-verifying-the-privileges-assigned-to-roles-against-the-module-table-usages/#comment-2610</link>
		<dc:creator>Victor Bax</dc:creator>
		<pubDate>Tue, 24 Jan 2006 15:14:11 +0000</pubDate>
		<guid isPermaLink="false">http://technology.amis.nl/blog/?p=910#comment-2610</guid>
		<description><![CDATA[Hi Lucas,

I indeed meant that the relevant user was removed as a Repository user (not a database user, yet). When this was done obviously all sorts of privileges were dropped at the same time. Next my colleague (really!) realised that the user account she just dropped was &quot;important&quot; and she reinstated the user as a Repository, to no avail.

The reinstated user account is now available in the SDW_USERS table. When the ODWA is used to grant and revoke privileges, a difference can be detected in that some roles can grant more privileges than others. The reason for this is not clear.

I am still trying to make a match between the RAU on the one side and ODWA on the other. Stupid or what? In the RAU I am still wondering why there is no way of modifying properties. When you position the cursor on any USER the properties button comes alive. Not with the ROLES. So where are you supposed to modify the ROLES&#039; properties?

So seeking consolation in the ODWA for some reason (my colleague persists it is because this one user was deleted) certain roles just lack a number of options, like &#039;Grant role&#039;, &#039;Edit role properties&#039; and &#039;Reconcile role&#039;. Where or how can you add these privileges to the relevant roles?

Thanks, Lucas!


Victor]]></description>
		<content:encoded><![CDATA[<p>Hi Lucas,</p>
<p>I indeed meant that the relevant user was removed as a Repository user (not a database user, yet). When this was done obviously all sorts of privileges were dropped at the same time. Next my colleague (really!) realised that the user account she just dropped was &#8220;important&#8221; and she reinstated the user as a Repository, to no avail.</p>
<p>The reinstated user account is now available in the SDW_USERS table. When the ODWA is used to grant and revoke privileges, a difference can be detected in that some roles can grant more privileges than others. The reason for this is not clear.</p>
<p>I am still trying to make a match between the RAU on the one side and ODWA on the other. Stupid or what? In the RAU I am still wondering why there is no way of modifying properties. When you position the cursor on any USER the properties button comes alive. Not with the ROLES. So where are you supposed to modify the ROLES&#8217; properties?</p>
<p>So seeking consolation in the ODWA for some reason (my colleague persists it is because this one user was deleted) certain roles just lack a number of options, like &#8216;Grant role&#8217;, &#8216;Edit role properties&#8217; and &#8216;Reconcile role&#8217;. Where or how can you add these privileges to the relevant roles?</p>
<p>Thanks, Lucas!</p>
<p>Victor</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lucas Jellema</title>
		<link>http://technology.amis.nl/2005/11/23/oracle-designer-script-for-verifying-the-privileges-assigned-to-roles-against-the-module-table-usages/#comment-2609</link>
		<dc:creator>Lucas Jellema</dc:creator>
		<pubDate>Tue, 24 Jan 2006 14:14:45 +0000</pubDate>
		<guid isPermaLink="false">http://technology.amis.nl/blog/?p=910#comment-2609</guid>
		<description><![CDATA[Victor,

I am not entirely sure what your situation is. When you say &#039;deleted a user&#039;do you mean removed that user from the group of Repository Users? You cannot delete (drop) the Repository owner and continue to use the Repository - as the entire repository owner&#039;s database schema along with all Designer&#039;s database objects would have vanished. So the owner must still exist as a database user.

Is the situation such that the database user who owns the repository is not currently a user in the repository? Which sounds strange but could be the case. That would means that the  SDW_USERS table does not have a record where USERNAME=.

Please give me a little more information.

Lucas]]></description>
		<content:encoded><![CDATA[<p>Victor,</p>
<p>I am not entirely sure what your situation is. When you say &#8216;deleted a user&#8217;do you mean removed that user from the group of Repository Users? You cannot delete (drop) the Repository owner and continue to use the Repository &#8211; as the entire repository owner&#8217;s database schema along with all Designer&#8217;s database objects would have vanished. So the owner must still exist as a database user.</p>
<p>Is the situation such that the database user who owns the repository is not currently a user in the repository? Which sounds strange but could be the case. That would means that the  SDW_USERS table does not have a record where USERNAME=.</p>
<p>Please give me a little more information.</p>
<p>Lucas</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Victor Bax</title>
		<link>http://technology.amis.nl/2005/11/23/oracle-designer-script-for-verifying-the-privileges-assigned-to-roles-against-the-module-table-usages/#comment-2608</link>
		<dc:creator>Victor Bax</dc:creator>
		<pubDate>Tue, 24 Jan 2006 11:49:46 +0000</pubDate>
		<guid isPermaLink="false">http://technology.amis.nl/blog/?p=910#comment-2608</guid>
		<description><![CDATA[Hello Lucas,

At the moment I am struggling with a problem where a key user within the Repository environment (Designer 6.5.93.2.8) deleted another user who apparently installed the Repository in the very beginning. In the environment there is no account called something like REPOS_OWNER or REPOS_MANAGER. It appears that the owner in this Repository is D6I_OWNER, but somehow this account does not have sufficient privileges to grant rights to roles.

Do we need to run scripts to grant privileges to the D6I_OWNER in order to reinstate the original situation? The roles administration is done through the ODWA.

Hope you can quote some keywords that I can use.

Regards,


Victor Bax]]></description>
		<content:encoded><![CDATA[<p>Hello Lucas,</p>
<p>At the moment I am struggling with a problem where a key user within the Repository environment (Designer 6.5.93.2.8) deleted another user who apparently installed the Repository in the very beginning. In the environment there is no account called something like REPOS_OWNER or REPOS_MANAGER. It appears that the owner in this Repository is D6I_OWNER, but somehow this account does not have sufficient privileges to grant rights to roles.</p>
<p>Do we need to run scripts to grant privileges to the D6I_OWNER in order to reinstate the original situation? The roles administration is done through the ODWA.</p>
<p>Hope you can quote some keywords that I can use.</p>
<p>Regards,</p>
<p>Victor Bax</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lucas Jellema</title>
		<link>http://technology.amis.nl/2005/11/23/oracle-designer-script-for-verifying-the-privileges-assigned-to-roles-against-the-module-table-usages/#comment-2607</link>
		<dc:creator>Lucas Jellema</dc:creator>
		<pubDate>Thu, 24 Nov 2005 13:47:58 +0000</pubDate>
		<guid isPermaLink="false">http://technology.amis.nl/blog/?p=910#comment-2607</guid>
		<description><![CDATA[Darn. I had not thought of that. You know what: you bring that functionality in the script and I will cheer you on. Deal??

You are unfortunately right of course. Another &#039;weak spot&#039; is the fact that the script does not check for modules that were granted through nested roles - so even if a role may look OK, it is possible that it has been granted modules through nested roles that require database object privileges that are not also granted through these nested roles. However, if you check all roles, this discrepancy will at least be reported.]]></description>
		<content:encoded><![CDATA[<p>Darn. I had not thought of that. You know what: you bring that functionality in the script and I will cheer you on. Deal??</p>
<p>You are unfortunately right of course. Another &#8216;weak spot&#8217; is the fact that the script does not check for modules that were granted through nested roles &#8211; so even if a role may look OK, it is possible that it has been granted modules through nested roles that require database object privileges that are not also granted through these nested roles. However, if you check all roles, this discrepancy will at least be reported.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anton</title>
		<link>http://technology.amis.nl/2005/11/23/oracle-designer-script-for-verifying-the-privileges-assigned-to-roles-against-the-module-table-usages/#comment-2606</link>
		<dc:creator>anton</dc:creator>
		<pubDate>Thu, 24 Nov 2005 08:46:19 +0000</pubDate>
		<guid isPermaLink="false">http://technology.amis.nl/blog/?p=910#comment-2606</guid>
		<description><![CDATA[A very useful script (I work on the same project :) ), but not perfect: what happens if someone has &quot;All&quot; rights on a object, but not specific &quot;Select&quot;, &quot;Update&quot;, &quot;Insert&quot; or &quot;Delete&quot; rigths?]]></description>
		<content:encoded><![CDATA[<p>A very useful script (I work on the same project <img src='http://technology.amis.nl/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ), but not perfect: what happens if someone has &#8220;All&#8221; rights on a object, but not specific &#8220;Select&#8221;, &#8220;Update&#8221;, &#8220;Insert&#8221; or &#8220;Delete&#8221; rigths?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
