ibmi-brunch-learn

Announcement

Collapse
No announcement yet.

How do you block members of a group from deleting specific objects?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • How do you block members of a group from deleting specific objects?

    Recently had a user delete printer devices. They are limited user, they did it through Ops Navigator from what I can tell, job name was QZRCSRVS

  • #2
    Re: How do you block members of a group from deleting specific objects?

    How do you block members of a group from deleting specific objects?
    If a user deletes an object, then the user had the appropriate authority to delete the object. To block deletions, remove the authority.

    Exactly how to do that depends on how things are set up.

    You refer to "members of a group". Does that mean that the 'group' is the only profile that is authorized to the device? Is 'group' also the owner of the device? Is the device authority assigned directly via private authority or via an *AUTL? What are the OWNER() and GRPAUT() attributes of the "members of a group"?

    What authorities should 'group' have as a final result? What authorities should "members of a group" have?

    Note that one potential difficulty is that the owner of an object can always change the object's authority even when *EXCLUDEd from the object.
    Tom

    There are only two hard things in Computer Science: cache invalidation, naming things and off-by-one errors.

    Why is it that all of the instruments seeking intelligent life in the universe are pointed away from Earth?

    Comment

    Working...
    X