<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Understanding Business Objects Inheritance</title>
	<atom:link href="http://davidlai101.com/blog/2010/02/20/understanding-business-objects-inheritance/feed/" rel="self" type="application/rss+xml" />
	<link>http://davidlai101.com/blog/2010/02/20/understanding-business-objects-inheritance/</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Thu, 19 Aug 2010 07:09:49 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: David Lai</title>
		<link>http://davidlai101.com/blog/2010/02/20/understanding-business-objects-inheritance/comment-page-1/#comment-26</link>
		<dc:creator>David Lai</dc:creator>
		<pubDate>Tue, 23 Feb 2010 19:16:05 +0000</pubDate>
		<guid isPermaLink="false">http://davidlai101.com/blog/?p=233#comment-26</guid>
		<description>Hi Yoav,
Thanks for your view on security.
For your first issue, I wrote on my previous article that if you want to prevent someone from refreshing in his own mailbox, that the user should have the &quot;Copy objects to another folder&quot; rights disabled. By default, this is disabled until you get to the Schedule access level.

For the second issue, the only way to prevent that is to further customize your security.

Unfortunately the predefined security access levels may not provide the exact specs a System Administrator may want, however in most cases, security specs are satisfied.</description>
		<content:encoded><![CDATA[<p>Hi Yoav,<br />
Thanks for your view on security.<br />
For your first issue, I wrote on my previous article that if you want to prevent someone from refreshing in his own mailbox, that the user should have the &#8220;Copy objects to another folder&#8221; rights disabled. By default, this is disabled until you get to the Schedule access level.</p>
<p>For the second issue, the only way to prevent that is to further customize your security.</p>
<p>Unfortunately the predefined security access levels may not provide the exact specs a System Administrator may want, however in most cases, security specs are satisfied.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yoav</title>
		<link>http://davidlai101.com/blog/2010/02/20/understanding-business-objects-inheritance/comment-page-1/#comment-25</link>
		<dc:creator>Yoav</dc:creator>
		<pubDate>Tue, 23 Feb 2010 13:55:44 +0000</pubDate>
		<guid isPermaLink="false">http://davidlai101.com/blog/?p=233#comment-25</guid>
		<description>Hi David,

Thanks for the great explanation,
I have many problems with the security system in CMC but I have two in mind for now:
1.Even if a user is just a &quot;refresh&quot; guy, as soon as he gets a report to his inbox he can edit it since he has full ownership on his inbox, this can of course be adjusted but as a beginner it is a security breach, many organizations I work with attend to miss that &quot;hole&quot;.
2. Another major issue: security will be always very limited as long as people who don&#039;t have the right to a universe can still get the result and watch it since they are not activating the universe in view mode.
Since you can&#039;t always turn all the queries in your repo to refresh on open it would be wise to my perspective to also allow security in the view level:
When a report is opened, its universe id is recognized and checked against the user rights, if he isn&#039;t allowed to use the universe, the report won&#039;t open as well.
Which security problems do you recognize in the CMC security mechanism ?

Best regards

Yoav</description>
		<content:encoded><![CDATA[<p>Hi David,</p>
<p>Thanks for the great explanation,<br />
I have many problems with the security system in CMC but I have two in mind for now:<br />
1.Even if a user is just a &#8220;refresh&#8221; guy, as soon as he gets a report to his inbox he can edit it since he has full ownership on his inbox, this can of course be adjusted but as a beginner it is a security breach, many organizations I work with attend to miss that &#8220;hole&#8221;.<br />
2. Another major issue: security will be always very limited as long as people who don&#8217;t have the right to a universe can still get the result and watch it since they are not activating the universe in view mode.<br />
Since you can&#8217;t always turn all the queries in your repo to refresh on open it would be wise to my perspective to also allow security in the view level:<br />
When a report is opened, its universe id is recognized and checked against the user rights, if he isn&#8217;t allowed to use the universe, the report won&#8217;t open as well.<br />
Which security problems do you recognize in the CMC security mechanism ?</p>
<p>Best regards</p>
<p>Yoav</p>
]]></content:encoded>
	</item>
</channel>
</rss>
