Results for “oke_compiled_access_rules_n2”

10 results




AI-generated from documented ETRM metadata — verify critical details on the linked pages.

Overview

OKE.OKE_COMPILED_ACCESS_RULES is a seed data table within the Oracle E-Business Suite Contracts (OKE) module that stores compiled access rule information. It defines the security model governing which contract roles may view or modify specific attributes and attribute groups on secured objects. Each row represents a resolved grant — a decision linking a contract role to a secured object and attribute — so that security checks during contract authoring and amendment do not require re-evaluation of the underlying rule hierarchy at runtime. The table resides in the APPS_TS_SEED tablespace, consistent with its role as reference and setup data maintained by Oracle rather than high-volume transactional data.

The heuristic Data Vault classification mined from the foreign key structure is link, and this is a reasonable modeling suggestion: the table's essence is an association among three independent business entities — the contract role, the secured object/attribute, and the access rule identifier — each of which has its own identity elsewhere in the schema. The access level and audit columns are descriptive payload carried on that link rather than attribute groups warranting a separate satellite.

Key Information Stored

The surrogate primary key is OKE_COMPILED_ACCESS_RULES_UK01 over ROLE_ID, SECURED_OBJECT_NAME, ATTRIBUTE_GROUP_TYPE, ATTRIBUTE_GROUP_CODE, and ATTRIBUTE_CODE. The unique index OKE_COMPILED_ACCESS_RULES_U1 covers the same logical business key minus ATTRIBUTE_GROUP_TYPE. Note that no single numeric surrogate column is documented as the primary key; the business key itself enforces uniqueness.

Common Use Cases and Queries

The most frequent diagnostic scenario is determining why a given contract role can or cannot see an attribute. Querying by the unique index prefix — ROLE_ID with SECURED_OBJECT_NAME — returns the compiled grants efficiently:

  • Security auditing: SELECT ROLE_ID, SECURED_OBJECT_NAME, ATTRIBUTE_CODE, ACCESS_LEVEL, ACCESS_RULE_ID FROM OKE.OKE_COMPILED_ACCESS_RULES WHERE ROLE_ID = :role_id ORDER BY SECURED_OBJECT_NAME, ATTRIBUTE_GROUP_CODE, ATTRIBUTE_CODE;
  • Failure analysis: when an expected attribute is missing, compare compiled rows against OKE_K_ACCESS_RULES to detect stale or absent compilation.
  • Reporting: joining to PA_PROJECT_ROLE_TYPES to render human-readable role names, or to OKE_OBJECT_ATTRIBUTES_B for attribute descriptions, supports access-matrix reports.
  • Form behavior verification: filtering on FORM_ITEM_FLAG = 'Y' identifies which secured attributes are exposed through the contract forms.

Related Objects

  • PA_PROJECT_ROLE_TYPES — joined via ROLE_ID; supplies role name and description for every compiled grant.
  • OKE_K_ACCESS_RULES — joined via ACCESS_RULE_ID; the source rule definitions from which compiled rows are generated.
  • OKE_OBJECT_ATTRIBUTES_B — joined via SECURED_OBJECT_NAME; defines the secured objects and their attributes.
  • OKE_COMPILED_ACCESS_RULES_N1 and OKE_COMPILED_ACCESS_RULES_N2 — non-unique indexes supporting lookups by secured object and attribute combinations.
  • OKE_COMPILED_ACCESS_RULES_U1 — the unique index most often referenced by name in tuning and integrity checks.