<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stored Process for Portal but not for Enterprise Guide users in Developers</title>
    <link>https://communities.sas.com/t5/Developers/Stored-Process-for-Portal-but-not-for-Enterprise-Guide-users/m-p/64802#M3278</link>
    <description>Hi Steve,&lt;BR /&gt;
&lt;BR /&gt;
Are your EG users also your Portal users? If not, how about creating two groups in SMC? One for your Portal users and the other for your EG users? Then deny read of your SP to the EG group. &lt;BR /&gt;
&lt;BR /&gt;
Milton</description>
    <pubDate>Sat, 06 Mar 2010 06:34:39 GMT</pubDate>
    <dc:creator>milts</dc:creator>
    <dc:date>2010-03-06T06:34:39Z</dc:date>
    <item>
      <title>Stored Process for Portal but not for Enterprise Guide users</title>
      <link>https://communities.sas.com/t5/Developers/Stored-Process-for-Portal-but-not-for-Enterprise-Guide-users/m-p/64801#M3277</link>
      <description>Has anyone solved this puzzle? &lt;BR /&gt;
&lt;BR /&gt;
I'd like to be able to create an SP to be run from the Portal that can report on secure data, and use Stored Process Server to get efficient execution (don't want each query to start its own workspace) but prevent Enterprise Guide users from running their own code on the same Stored Process Server and circumventing data security by running under the server identity.&lt;BR /&gt;
&lt;BR /&gt;
If I secure the Logical Stored Process server in metadata I can prevent EG users from connecting to it ... but then if one of those users logs on to the Portal they can't run the canned Stored Process because the server is not available to them. If it's available to the Portal I can't see any way to stop the EG user running an SP there.&lt;BR /&gt;
&lt;BR /&gt;
Is there some way to set up an SP server that the Portal can use, but which EG users can't see?&lt;BR /&gt;
&lt;BR /&gt;
This is under 9.1.3 by the way, so a 9.2 method won't help (at least not for a while)&lt;BR /&gt;
&lt;BR /&gt;
I wait in hope,&lt;BR /&gt;
&lt;BR /&gt;
Steve</description>
      <pubDate>Thu, 04 Mar 2010 16:49:06 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Developers/Stored-Process-for-Portal-but-not-for-Enterprise-Guide-users/m-p/64801#M3277</guid>
      <dc:creator>deleted_user</dc:creator>
      <dc:date>2010-03-04T16:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: Stored Process for Portal but not for Enterprise Guide users</title>
      <link>https://communities.sas.com/t5/Developers/Stored-Process-for-Portal-but-not-for-Enterprise-Guide-users/m-p/64802#M3278</link>
      <description>Hi Steve,&lt;BR /&gt;
&lt;BR /&gt;
Are your EG users also your Portal users? If not, how about creating two groups in SMC? One for your Portal users and the other for your EG users? Then deny read of your SP to the EG group. &lt;BR /&gt;
&lt;BR /&gt;
Milton</description>
      <pubDate>Sat, 06 Mar 2010 06:34:39 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Developers/Stored-Process-for-Portal-but-not-for-Enterprise-Guide-users/m-p/64802#M3278</guid>
      <dc:creator>milts</dc:creator>
      <dc:date>2010-03-06T06:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Stored Process for Portal but not for Enterprise Guide users</title>
      <link>https://communities.sas.com/t5/Developers/Stored-Process-for-Portal-but-not-for-Enterprise-Guide-users/m-p/64803#M3279</link>
      <description>Hi Milton,&lt;BR /&gt;
&lt;BR /&gt;
Good idea, but the there is overlap between Portal users and EG users, so I can't segregate them that way.&lt;BR /&gt;
&lt;BR /&gt;
I was wondering about setting up an SP server running under a different identity (rather than sassrv, something with a bit lower privilege that can't see the data by default) and then use a compiled macro to access the required hidden path, but only if the 'right' _PROGRAM value is present. Seems a bit convoluted, so I was hoping someone had found a better method before I try setting all that up.&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Steve</description>
      <pubDate>Sat, 06 Mar 2010 12:13:18 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Developers/Stored-Process-for-Portal-but-not-for-Enterprise-Guide-users/m-p/64803#M3279</guid>
      <dc:creator>deleted_user</dc:creator>
      <dc:date>2010-03-06T12:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: Stored Process for Portal but not for Enterprise Guide users</title>
      <link>https://communities.sas.com/t5/Developers/Stored-Process-for-Portal-but-not-for-Enterprise-Guide-users/m-p/64804#M3280</link>
      <description>Hi:&lt;BR /&gt;
   I'm not clear on whether it is even POSSIBLE to set up a Stored Process Server that would use an identity other than sassrv. To me, that would be a question for SAS Technical Support. This documentation suggests that it is possible to hide server definitions from certain users:&lt;BR /&gt;
&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/61133/HTML/default/a003280630.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/61133/HTML/default/a003280630.htm&lt;/A&gt; &lt;BR /&gt;
&lt;BR /&gt;
  It does not outline a way to bypass the use of sassrv or SAS General Servers group.&lt;BR /&gt;
 &lt;BR /&gt;
cynthia</description>
      <pubDate>Sat, 06 Mar 2010 15:42:45 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Developers/Stored-Process-for-Portal-but-not-for-Enterprise-Guide-users/m-p/64804#M3280</guid>
      <dc:creator>Cynthia_sas</dc:creator>
      <dc:date>2010-03-06T15:42:45Z</dc:date>
    </item>
  </channel>
</rss>

