如何通过DQL查询Documentum对象的访问控制列表及ACL数量疑问
Hey there! Since you're new to Documentum, let's walk through your questions about Access Control Lists (ACLs) clearly and simply—no jargon overload, promise 😊
There are two common ways to get ACL info for an object, depending on how much detail you need:
Basic ACL Identification
If you just need to know which ACL is assigned to the object (its name and domain), use this simple DQL query. Replace the r_object_id value with your target object's ID:
SELECT acl_name, acl_domain FROM dm_document WHERE r_object_id = '0900d28880001234'
Every Documentum object has acl_name and acl_domain properties that together uniquely identify its assigned ACL.
Detailed ACL Permissions
If you want to see the specific permissions (which users/groups have access, and what level of access), join the object table with dm_acl and dm_acl_permit (the table that stores individual permission entries):
SELECT a.acl_name, a.acl_domain, p.permittee_name, p.permittee_domain, p.accessor_permit FROM dm_document obj JOIN dm_acl a ON obj.acl_name = a.object_name AND obj.acl_domain = a.owner_name JOIN dm_acl_permit p ON a.r_object_id = p.acl_id WHERE obj.r_object_id = '0900d28880001234'
accessor_permituses numeric codes to represent permission levels (e.g., 7 = Full Control, 6 = Modify, 5 = Read, etc.)- This query will return every user/group and their corresponding access level for the object's ACL.
Short answer: No, each Documentum object can only have one primary ACL assigned to it at any time.
That said, there are a few related scenarios that might make it seem like multiple ACLs are in play:
- You can easily replace an object's existing ACL with a different one (using API commands like
set,c,acl_nameor a DQLUPDATEstatement) - Extended Permissions: These are additional, granular permission settings that supplement the primary ACL. They let you add or restrict access for specific users/groups without replacing the entire ACL, but they aren't separate ACLs—they're stored in the
dm_acl_ext_permittable and work alongside the main ACL. - Folder Inheritance: Objects in a folder might inherit the folder's ACL by default, but once you assign a unique ACL to the object itself, it stops inheriting and uses its own single ACL.
内容的提问来源于stack exchange,提问作者Akhil

