This content has been marked as final. Show 5 replies
I don't believe this is any way round this because as soon as you enter admin mode the user has access to all the folders and functionality. The only way would be to restrict access to ORCLADMIN user but this would be dangerous as depending on how you set this you may never be able to set the security back.
An alternative would be to create a not-so-SUPER user and use this instead, and keep the ORCLADMIN password secure.
This new user could have some form of diminished responsibilities. i.e won't be able to switch to administration mode, hence see these files/folders where sharing has not been granted
thanks for your request. But this is not so good solution for me :( ....
Do you think that "Oracle DB Vault" can help me ?!!?...
I think we were going to go down the route of DB Vault at some point but I think the licensing costs and timescales went against us. one other option might be VPD polices on the Content DB but not sure how the web client would handle this.
Still don't know if having the ORCLADMIN password widely available is a good. If say however your application is SSO enabled it means you could potentially opening yourself up for widespread access to other applications.
sorry I couldn't be of help.
By default orcladmin gets all admin roles, try to right click on the folder you want to change and see if you can revoke the content administrator privilege for orcladmin on that folder as a different user(admin user on that folder who can see these secret documents.(Again you need to make sure that you manage these security privileges properly - plan out what you want and what you dont).
Hope that helps.
I think you should raise a SR before doing that, it should have unknown side effects, orcladmin is a special user