Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Content Management (Extended ECM)
API, SDK, REST and Web Services
LiveReport - Changing permissions on Workflow Attachments (by Mass)
Lance_Griffith_(SPPARAdmin_(Delete)_2261001)
I have been cranking thru sql scripts trying to find the right combination that would help me change all of my completed workflow attachment permissions. We have a Salary Increase workflow that has two attachments. 1.) is a link to the application that allows one to input data in a form and 2.) the form is saved to the workflow as an attachment. It just came to our attention that ALL of the attachments with salary information is exposed to the public. Unfortunately, we have around 600 workflows that need permission changes. I would appreciate any HELP.....
Find more posts tagged with
Comments
eLink User
Message from Alex Kowalenko via eLinkdo you need help with locating the workflow attachments or the properbitmask values for the new permissions you want to assign to them?-----Original Message-----From: knowledge@opentext.com [mailto:knowledge@opentext.com]On Behalf OfeLink Discussion: Livelink LiveReports DiscussionSent: Tuesday, November 06, 2001 18:23To: eLink RecipientSubject: LiveReport - Changing permissions on Workflow Attachments (byMass)LiveReport - Changing permissions on Workflow Attachments (by Mass)Posted by SPPARAdmin on 11/06/2001 06:18 PMI have been cranking thru sql scripts trying to find the right combinationthat would help me change all of my completed workflow attachmentpermissions. We have a Salary Increase workflow that has two attachments.1.) is a link to the application that allows one to input data in a form and2.) the form is saved to the workflow as an attachment. It just came to ourattention that ALL of the attachments with salary information is exposed tothe public. Unfortunately, we have around 600 workflows that needpermission changes. I would appreciate any HELP.....[To reply to this thread, use your normal e-mail reply function.]============================================================Discussion: Livelink LiveReports Discussion
https://knowledge.opentext.com/knowledge/livelink.exe?func=ll&objId=2249677&objAction=viewLivelink
Server:
https://knowledge.opentext.com/knowledge/livelink.exe
Lance_Griffith_(SPPARAdmin_(Delete)_2261001)
Alex,I have used the below script to locate the attachments, but now I need to determine which perms are the correct ones to change, I am guessing it is the wpermissions, since this would be related to public access.select name||' '||dataid||' '||permID||' '||spermissions||' '||upermissions||' '||wpermissionsfrom dtreewhere subtype = '154'order by permID/***************************(What would the script that makes the mass change look like?)It would definately help to know the bit mask that I need to change it to, I want to make the attachments un searchable to all public guest. I am not totally clear how the bitmask are generated. So, with that said, I truly appreciate you help.
John W. Simon, Jr.
RayAnn,If you have the SDK you should look into using it for this. The reason is that it automatically knows all of the places to change permissions when you make your calls (assuming you do DAPI calls not CAPI calls).If not, I have found that changing DTREE is not enough. You will also have to change DTREEACL as it is the table that really controls permissions.Regards,John Simon
Alex_Kowalenko_(akowalen_(Delete)_2285456)
I agree with John that the SDK is the best tool to use if you want to make changes to the Livelink database. In my Schema and LiveReports courses I emphasize this point.But if you must make changes to the permissions then the bitmasks in DTree.Permissions and DTreeACL.Permissions must be changed.In your case, if you want to turn all Public Access permissions off, then the bitmask is bit 7 on and all others off which equals to decimal 128. You change DTree.WPermissions and DTreeACL.Permissions to 128 for all DataID's of your workflow attachments where DTreeACL.RightID is -1. You would also have to do this for all children and grandchidrel, etc. of the workflow attachment folders.The Oracle SQL would be something like this:For DTree.WPermissions:UPDATE DTREE SET WPERMISSIONS = 128WHERE DATAID IN(SELECT DATAID FROM DTREESTART WITH DATAID IN(SELECT DATAID FROM DTREEWHERE SUBTYPE = 154)CONNECT BY PRIOR DATAID = PARENTID)For DTreeACL.Permissions:UPDATE DTREEACL SET PERMISSIONS = 128WHERE DATAID IN(SELECT DATAID FROM DTREESTART WITH DATAID IN(SELECT DATAID FROM DTREEWHERE SUBTYPE = 154)CONNECT BY PRIOR DATAID = PARENTID)AND RIGHTID = -1If you are using an SQL worksheet don't forget the COMMIT commands.