This forum is closed to new posts and
responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:
They have their use, but you shouldn't leave your security to just roles. It leaves you open to other issues.
For what you want to do I can't see the reason why you don't have it run as the web user. If you want you can check the web users role at that point.
Another option I have seen is you have Agent which the user calls (runs as web user). It creates a signed document in another database. A scheduled agent then runs against documents created there and processes them. The second agent cannot be run from the Web and runs under different credentials.
But that has its own pros and cons.
Feedback response number WEBB8F9SZH created by ~Joseph Fezlulitynds on 03/24/2011