﻿{"id":1494,"date":"2022-12-11T19:25:28","date_gmt":"2022-12-11T13:55:28","guid":{"rendered":"https:\/\/blogs.infosys.com\/infosys-cobalt\/?p=1494"},"modified":"2022-12-11T19:25:28","modified_gmt":"2022-12-11T13:55:28","slug":"provisioning-permissions-to-access-action-codes-on-the-basis-of-the-type-of-user","status":"publish","type":"post","link":"https:\/\/blogs.infosys.com\/infosys-cobalt\/cloud-applications\/oracle\/provisioning-permissions-to-access-action-codes-on-the-basis-of-the-type-of-user.html","title":{"rendered":"PROVISIONING PERMISSIONS TO ACCESS ACTION CODES ON THE BASIS OF THE TYPE OF USER"},"content":{"rendered":"<p>User\u2019s access can be managed in two ways:<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Allowed Actions &#8211; Refer to the actions that can be performed on a hierarchy through a request.<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Property Access &#8211; Establishing controls as far as the properties that will be visible and editable at the node type level.<\/p>\n<p>&nbsp;<\/p>\n<p>Solution Approach:<\/p>\n<p>In order to meet a client\u2019s requirement, we provisioned one user with \u2018Participant Write\u2019 permission and as a part of the configuration we allowed the ADD and DELETE action codes. A user with the permission to ADD nodes also has the permission to UPDATE nodes.<\/p>\n<p>Similarly, for another user with \u2018Participant Write\u2019 permission we configured the MOVE, REMOVE, and REORDER action codes.<\/p>\n<p>&nbsp;<\/p>\n<p>Expected Outcome:<\/p>\n<p>MOVE, REMOVE, and REORDER action codes should be disabled for User 1 whereas ADD and DELETE options should be disabled for User 2.<\/p>\n<p>&nbsp;<\/p>\n<p>Important point to note:<\/p>\n<p>To Add nodes in a hierarchy, both the ADD action on the NODE TYPE and INSERT action on the hierarchy set are required. To Delete nodes from a hierarchy, both the DELETE action on the node type and REMOVE action on the hierarchy set are required.<\/p>\n<p>The blog will showcase this scenario:<\/p>\n<p>Refer to the below table:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1476\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Table-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Configuring the 2 Users:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1477\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Table-2.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>1) As mentioned in the table above, ADD and DELETE action codes are provisioned for Alex Smith. Hence, the other action codes should be disabled for Alex Smith. The following snapshot is of the \u2018Permissions\u2019 tab in the node type level. Refer to Snapshot 1 below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1479\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Snapshot-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>2) Similarly, MOVE, REMOVE and REORDER action codes are allowed for James Bird so other action codes should be disabled for him. The following snapshot is of the Permissions tab in the hierarchy set level. Refer to Snapshot 2 below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1480\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Snapshot-2-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>3)I logged in as Alex Smith to ADD a new node. Refer to Snapshot 3 below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1467\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Snapshot-3-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Notice that every other action code except ADD and DELETE is disabled, which is what was expected as per the configurations that we have done.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>4) Below is the snapshot to showcase the error message that we get if INSERT action code is not allowed in hierarchy level permissions when ADD is allowed in the node type level permissions. Refer to Snapshot 4 below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1468\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Snapshot-4-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>5) To get rid of the error message, I added INSERT as an allowed action code in the hierarchy set level permissions for User1. The expectation now is that I will be able to ADD a new node. Refer to Snapshot 5 below.<\/p>\n<p>Note: This user already has \u2018Add\u2019 and \u2018Delete\u2019 action enabled at Node Type level.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1469\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Snapshot-5-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>6) I created a new request- Request 3862 to ADD a new sibling to the node \u2018000\u2019. Refer to Snapshot 6 below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1470\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Snapshot-6-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>7)The new node \u2018001\u2019 gets added as a sibling of 000. Refer to Snapshot 7 below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1471\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Snapshot-7-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>8) Now I\u2019ll login as James Bird who cannot ADD or DELETE nodes but can only MOVE, REMOVE or REORDER nodes. Refer to Snapshot 8 below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1472\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Snapshot-8-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Notice that as we configured, every action code except MOVE, REMOVE and REORDER is disabled.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>9) Next, I\u2019ll showcase the REMOVE action code. Note the node \u2018000\u2019 existing as a child of the parent node \u2018T\u2019. Refer to Snapshot 9 below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1473\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Snapshot-9-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>10) Click on the REMOVE option from the drop-down menu. Refer to Snapshot 10 below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1474\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Snapshot-10-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>11) \u00a0The node \u2018000\u2019 gets removed. Refer to Snapshot 11 below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1475\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Snapshot-11-1.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>To conclude, below is the configuration required to fulfil this requirement which is valid for all other similar scenarios:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1478\" src=\"https:\/\/blogs.infosys.com\/infosys-cobalt\/storage\/2022\/11\/Table-3.jpg\" alt=\"\" width=\"1152\" height=\"648\" \/><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>User\u2019s access can be managed in two ways: \u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Allowed Actions &#8211; Refer to [&hellip;]<\/p>\n","protected":false},"author":312,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[69,72],"tags":[158,166,159],"coauthors":[155],"class_list":["post-1494","post","type-post","status-publish","format-standard","hentry","category-oracle","category-oracle-cloud-infrastructure","tag-edm","tag-edmuserprovisioning","tag-metadatamaintenance"],"acf":[],"_links":{"self":[{"href":"https:\/\/blogs.infosys.com\/infosys-cobalt\/wp-json\/wp\/v2\/posts\/1494","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.infosys.com\/infosys-cobalt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.infosys.com\/infosys-cobalt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.infosys.com\/infosys-cobalt\/wp-json\/wp\/v2\/users\/312"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.infosys.com\/infosys-cobalt\/wp-json\/wp\/v2\/comments?post=1494"}],"version-history":[{"count":4,"href":"https:\/\/blogs.infosys.com\/infosys-cobalt\/wp-json\/wp\/v2\/posts\/1494\/revisions"}],"predecessor-version":[{"id":1587,"href":"https:\/\/blogs.infosys.com\/infosys-cobalt\/wp-json\/wp\/v2\/posts\/1494\/revisions\/1587"}],"wp:attachment":[{"href":"https:\/\/blogs.infosys.com\/infosys-cobalt\/wp-json\/wp\/v2\/media?parent=1494"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.infosys.com\/infosys-cobalt\/wp-json\/wp\/v2\/categories?post=1494"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.infosys.com\/infosys-cobalt\/wp-json\/wp\/v2\/tags?post=1494"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.infosys.com\/infosys-cobalt\/wp-json\/wp\/v2\/coauthors?post=1494"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}