To all concerned,
In a previous thread (https://community.emc.com/message/754423) PanfilovAB provided a great solution to address a unique business requirement
The requirement is to prevent a specific user from viewing a document if the document is about themselves.
The solution entails using a TBO to apply an AliasSet to a templated ACL to dynamically set an AccessRestriction rule. However, the solution requires one AliasSet to be created per user. This involves a good deal of maintainence as in this case thousands of users will be added during the course of a year with an initial user base of 50,000 users.
I believe it would be possible to dynamically create an AliasSet every time a doSave() event is triggered just to set the user name on the ACL template. What would be the downside to doing the following:
@Override
protected synchronized void doSave( boolean saveLock, String versionLabel, Object[] extendedArgs )
throws DfException
{
//-----------------------------------------------------
// Get Session information
IDfSession idfSess = getSession();
String strTStamp = timeStamp(); // some custom unique timestamp string
String strAliasSetOrig = idfSess.getAliasSet();
//-----------------------------------------------------
// Create new Alias Set on fly
IDfAliasSet idfAliasSet = (IDfAliasSet) idfSess.newObject("dm_alias_set");
idfAliasSet.setString( "owner_name", "dm_dbo" );
idfAliasSet.setObjectName( strTStamp );
idfAliasSet.appendAlias( "related_to", // String name
"username", // String value
IDfAliasSet.CATETORY_USER, // int category
0, // int userCategory
"Temporary User Name" ); // String description
idfAliasSet.save();
//-----------------------------------------------------
// Set Session Alias Set to the new Alias Set
idfSess.setAliasSet( strTStamp );
//-----------------------------------------------------
// Apply ACL Template
this.setACLDomain( "dm_dbo" );
this.setACLName( strACL );
//-----------------------------------------------------
// Invoke Super Save
super.doSave( saveLock, versionLabel, extendedArgs );
//-----------------------------------------------------
// Set Session Alias Set back to original
idfSess.setAliasSet( strAliasSetOrig );
//-----------------------------------------------------
// Destroy temporary Alias Set
idfAliasSet.destroy();
}