Re: WebDB user/component security

From: Thomas Kyte <tkyte_at_us.oracle.com>
Date: Sat, 31 Jul 1999 18:45:41 GMT
Message-ID: <37a643e8.10025175_at_newshost.us.oracle.com>


A copy of this was sent to psalmu_at_my-deja.com (if that email address didn't require changing) On Fri, 30 Jul 1999 18:31:09 GMT, you wrote:

>If you want a little laugh, look at function
>WEBDB.WWV_USER_SECURITY.check_privilege,
>which is supposed to check if a user can execute a component, unless
>I have misunderstood this completely. The checking doesn't look
>quite as strict as you might expect...
>

that function currently is a no-op. all component access privs are currently checked by the database (you either have been granted the ability to run a component or not) not by the runtime.

the function you are looking at is in there for a future release, to allow for other authorization mechanisms to be used. its just placeholder right now.

>
>Sent via Deja.com http://www.deja.com/
>Share what you know. Learn what you don't.

-- 
See http://govt.us.oracle.com/~tkyte/ for my columns 'Digging-in to Oracle8i'...
Current article is "Part I of V, Autonomous Transactions" updated June 21'st
 
Thomas Kyte                   tkyte_at_us.oracle.com
Oracle Service Industries     Reston, VA   USA

Opinions are mine and do not necessarily reflect those of Oracle Corporation
Received on Sat Jul 31 1999 - 20:45:41 CEST

Original text of this message