<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization Issue in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-issue/m-p/5546056#M1266277</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; We cannot remove other roles due to bussiness compulsion. Is there any other way we can restrict the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP security is about allowing, not restricting. I guess you'd need to build an extra authority-check into your report which checks an additional (bespoke) object that isn't used by other programs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the fact that the user is obviously allowed to view other company codes makes me wonder why this restriction should be tighter for a specific report.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Apr 2009 07:48:35 GMT</pubDate>
    <dc:creator>jurjen_heeck</dc:creator>
    <dc:date>2009-04-29T07:48:35Z</dc:date>
    <item>
      <title>Authorization Issue</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-issue/m-p/5546055#M1266276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Freinds,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a report created in report painter 'FSI0' (Standard Tcode). We want to restrict the user authorization for this report in 'FSI0' on the company code authorization object. We are using 'F_BKPF_BUK' object in the role creation with company code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that this role restricts the user on the object 'F_BKPF_BUK' for a particular company code, but there are other roles which are attached to the user giving access to other company codes. Hence the role gets bypassed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We cannot remove other roles due to bussiness compulsion. Is there any other way we can restrict the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thnks.&lt;/P&gt;&lt;P&gt;RR&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Apr 2009 07:25:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-issue/m-p/5546055#M1266276</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-29T07:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-issue/m-p/5546056#M1266277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; We cannot remove other roles due to bussiness compulsion. Is there any other way we can restrict the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP security is about allowing, not restricting. I guess you'd need to build an extra authority-check into your report which checks an additional (bespoke) object that isn't used by other programs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the fact that the user is obviously allowed to view other company codes makes me wonder why this restriction should be tighter for a specific report.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Apr 2009 07:48:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-issue/m-p/5546056#M1266277</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2009-04-29T07:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-issue/m-p/5546057#M1266278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This message was moderated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 May 2009 07:13:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-issue/m-p/5546057#M1266278</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-05-27T07:13:14Z</dc:date>
    </item>
  </channel>
</rss>

