Hi All,
I am looking for some clarity on the best practices when utilizing a UPS with XSA.
I understand the UPS user is used to execute the .hdbgrants file which grants auths to the object_owner, application users, etc but I want to know if the UPS should actually be used in querying data directly itself to the schemas in the DB?
In my scenario, the UPS user is being used to access virtual schemas on the underlying DB, so in order to allow the container access, we used a UPS user to grant the auths to the object_owner so it can view the tables in the schema. My understanding is a bit unclear when it comes to the process around querying the data then, as the UPS has already granted the ability to the #OO user and to application users via synonyms, should the UPS ever be the one who then querying the data from the schema? I would expect the answer to be no but I have been receiving conflicting information and would really appreciate a simplfoed answer to this.
Many thanks,
Michael