<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No display authorization in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982701#M1160970</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vanitha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What steps are you planning on taking to stop the user being able to add back the access to be able to view the code?  SAP_ALL without certain S_PROGRAM or S_DEVELOP authorisations will still give the user the ability to assign themselves different access, create a new user etc.  They can also trash the system!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Jan 2009 12:55:15 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-01-08T12:55:15Z</dc:date>
    <item>
      <title>No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982690#M1160959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created an User and given him SAP_ALL authorizations. Now the requirement is, that user should have all the authorizations like SAP_ALL expect he should not be able to view the source code of the program in SA38. He shoule be able to execute it, but not able to display the source code. Any role that i can create with this criteria. Please i need you suggestions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Vanitha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Vanitha badampudi on Jan 8, 2009 11:07 AM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Vanitha badampudi on Jan 8, 2009 11:08 AM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 10:06:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982690#M1160959</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-08T10:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982691#M1160960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am certain that you can not achieve the described restriction while the users has SAP_ALL profile assigned to him/her.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's the entire point of SAP_ALL (and its cousin SAP_NEW).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can not create a role to &lt;STRONG&gt;restrict&lt;/STRONG&gt;, you can only create a role to allow - SAP security uses whitelisting, not blacklisting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 10:22:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982691#M1160960</guid>
      <dc:creator>Private_Member_119218</dc:creator>
      <dc:date>2009-01-08T10:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982692#M1160961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;two possible options:&lt;/P&gt;&lt;P&gt;1 create your own SAP_ALL (copy profile SAP_ALL into a role into the profile generator and limit that) take out all change/create in S_Program.&lt;/P&gt;&lt;P&gt;2 create a role with ONLY SA38 and be sure not to give other activities than display in any object. Secodnly create role for all other access this user needs and be sure not to give wider access in any object than display as far as the objects are the same as in teh SA38 role,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second option is better , besides one should NEVER| give SAP_ALL in ANY SAP system!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 10:32:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982692#M1160961</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-08T10:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982693#M1160962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vanitha,&lt;/P&gt;&lt;P&gt;I think ,you can not restrict only display authorization allowing user execute activity. While executing any program in SE38, it also checkes for 03 actvt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sneha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 10:32:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982693#M1160962</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-08T10:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982694#M1160963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thankyou for that answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is, can i create a role which  has all the authorizations except that a user cannot view the source code of a program. if there is a possiblity to create a role, what should be the authorization objects that i can assign to that role apart from S_Develop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;/P&gt;&lt;P&gt;Vanitha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 10:34:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982694#M1160963</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-08T10:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982695#M1160964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Auke. SA38 will check S_PROGRAM to submit the report and not S_DEVELOP to display the source code unless the user runs a report which does that - but then the S_DEVELOP checks will kick in again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 10:46:59 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982695#M1160964</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-08T10:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982696#M1160965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;when you use SA38 and in S_PROGRAM only allow for activity submit than there is no way of displaying&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 11:11:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982696#M1160965</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-08T11:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982697#M1160966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But without S_develop , it does not allow to execute any program.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 11:31:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982697#M1160966</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-08T11:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982698#M1160967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; But without S_develop , it does not allow to execute any program.&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;Not true. It will however depend on your choice of transaction (that is why the choice of transaction is important when designing roles for processes...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, even VARIANT as P_ACTION of S_PROGRAM is enough to submit it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 12:43:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982698#M1160967</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-08T12:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982699#M1160968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But if user want to execute the program to Se38 only , then S_develop is mandatory.Without S_DEVELOP authorization object it will not allow to execute tcode too. As Julius said " It will however depend on your choice of transaction "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sneha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 12:50:16 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982699#M1160968</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-08T12:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982700#M1160969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; But if user want to execute the program to Se38 only , then S_develop is mandatory.Without S_DEVELOP authorization object it will not allow to execute tcode too. As Julius said " It will however depend on your choice of transaction "&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;Stated like that it is almost correct - SE38 is a report type program. The checks you are refering to happen when you &lt;STRONG&gt;start&lt;/STRONG&gt; the transaction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW: To tweak the concept further to meet your needs if you cannot restrict S_DEVELOP for what ever reasons, there are 2 exits which can be activated, one which will activate a check on actvt 16 of S_DEVELOP for object_type PROG... and another one in the editor with which you can do a lot more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But generally, restricting S_DEVELOP is the best and safest route to take.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Julius Bussche on Jan 8, 2009 2:00 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 12:53:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982700#M1160969</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-08T12:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982701#M1160970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vanitha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What steps are you planning on taking to stop the user being able to add back the access to be able to view the code?  SAP_ALL without certain S_PROGRAM or S_DEVELOP authorisations will still give the user the ability to assign themselves different access, create a new user etc.  They can also trash the system!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 12:55:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982701#M1160970</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-08T12:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982702#M1160971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Experts!,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem solved. I have created role with the selection criteria and removed all the authorization objects that are not needed according to the requirement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you all for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Vanitha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jan 2009 06:15:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982702#M1160971</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-09T06:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: No display authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982703#M1160972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we just need S_DEVELOP for SE38  or S_PROGRAM for SA38 to execute any program....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Jan 2009 01:31:07 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/no-display-authorization/m-p/4982703#M1160972</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-11T01:31:07Z</dc:date>
    </item>
  </channel>
</rss>

