Use PDIs? Take our 5-minute survey to help shape the PDI roadmap.

Security Attribute `RoleExplicit` description

NS
Kilo Sage

Hello,

 

I came across something misleading in the OOB Security Attribute `RoleExplicit`. The description of it is 

> User has the specified role explicitly, that is, it is present in the sys_user_has_role table.

NS_0-1788271164680.png

 

 

This seems to be completely wrong. The attribute seems to consider the sys_user_has_role.inherited instead.

In this case my user gets the role through a group membership -> "it is present in the sys_user_has_role table.". But the access is denied because the role is inherited=true

NS_1-1788271302200.png

 

 

Grant the role directly, and the user gains access as you would expect:

NS_2-1788271565317.png

 

 

This security attribute was discussed also in this community post, but it doesn't address the description. Hope someone finds this helpful or doesn't trust the description of the security attribute thanks to this!

 

0 REPLIES 0