<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hierarchy authorization in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/hierarchy-authorization/m-p/8096207#M1615926</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have upgraded our BI system to the new security approach 7. We created the corresponding roles/objects thru the RSECADMIN t-code for 0COUNTRY and some other infoObjects where the 0COUNTRY is navegational attribute, for example the 0COMP_CODE__0COUNTRY, and everything is workink fine.&lt;/P&gt;&lt;P&gt;The 0COUNTRY and (i.e.) the 0COMP_CODE__0COUNTRY are checked as Authorization Relevant.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, we want to create a hierarchy for the 0COUNTRY infoObject, and I would like to know if the security done at the value level is enought to restrict the data or we need to create some new roles/objects thru the RSECADMIN in order to do the same restriction done to the flat values now at the hierarchy.&lt;/P&gt;&lt;P&gt;We dont mind the intermediate nodes (regions), just the country values for the hierarchy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, we need the following hierarchy:&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;World
|_ Europe
	|_ Germany
	|_ Italy
	|_ Spain
|_ Asia
	|_ China
	|_ Japan&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With variable authorization we need:&lt;/P&gt;&lt;P&gt;If user has just Spain, show Spain.&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;World
|_ Europe
	|_ Spain&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If user has Germany, Italy, Spain.&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;World
|_ Europe
	|_ Germany
	|_ Italy
	|_ Spain&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If user has *.&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;World
|_ Europe
	|_ Germany
	|_ Italy
	|_ Spain
|_ Asia
	|_ China
	|_ Japan&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now, without using hierarchy, the data is showing ok depending on the authorization that user has (allways using authorization variables in the query).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Federico&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 09 Jul 2011 01:47:24 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2011-07-09T01:47:24Z</dc:date>
    <item>
      <title>Hierarchy authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/hierarchy-authorization/m-p/8096207#M1615926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have upgraded our BI system to the new security approach 7. We created the corresponding roles/objects thru the RSECADMIN t-code for 0COUNTRY and some other infoObjects where the 0COUNTRY is navegational attribute, for example the 0COMP_CODE__0COUNTRY, and everything is workink fine.&lt;/P&gt;&lt;P&gt;The 0COUNTRY and (i.e.) the 0COMP_CODE__0COUNTRY are checked as Authorization Relevant.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, we want to create a hierarchy for the 0COUNTRY infoObject, and I would like to know if the security done at the value level is enought to restrict the data or we need to create some new roles/objects thru the RSECADMIN in order to do the same restriction done to the flat values now at the hierarchy.&lt;/P&gt;&lt;P&gt;We dont mind the intermediate nodes (regions), just the country values for the hierarchy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, we need the following hierarchy:&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;World
|_ Europe
	|_ Germany
	|_ Italy
	|_ Spain
|_ Asia
	|_ China
	|_ Japan&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With variable authorization we need:&lt;/P&gt;&lt;P&gt;If user has just Spain, show Spain.&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;World
|_ Europe
	|_ Spain&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If user has Germany, Italy, Spain.&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;World
|_ Europe
	|_ Germany
	|_ Italy
	|_ Spain&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If user has *.&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;World
|_ Europe
	|_ Germany
	|_ Italy
	|_ Spain
|_ Asia
	|_ China
	|_ Japan&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now, without using hierarchy, the data is showing ok depending on the authorization that user has (allways using authorization variables in the query).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Federico&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Jul 2011 01:47:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/hierarchy-authorization/m-p/8096207#M1615926</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-07-09T01:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Hierarchy authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/hierarchy-authorization/m-p/8096208#M1615927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, your approach is right. You can restrict the InfoObject 0COUNTRY and then maintain the country values in the Analysis Authorizations (its no more a hierarchy authorization). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The EQ can be used to maintain a single country (you need to add multiple EQs if you wish to add morethan 1 country in the same analysis authorization)&lt;/P&gt;&lt;P&gt;The CP can be used to maintain with a pattern such as A* countries etc&lt;/P&gt;&lt;P&gt;The BT can be used to give a range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, ensure that the user has authorization to all the Infoareas (bottom - up) and queries so that his/her authorization can be restricted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Raghu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Jul 2011 19:37:13 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/hierarchy-authorization/m-p/8096208#M1615927</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-07-09T19:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: Hierarchy authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/hierarchy-authorization/m-p/8096209#M1615928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to use Hierarchy, It is possible in all ways you wanted in BI7.0 analysis authorization....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see below options...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0	Only the Selected Nodes&lt;/P&gt;&lt;P&gt;1	Subtree Below Nodes&lt;/P&gt;&lt;P&gt;2	Subtree Below Nodes to Level (Incl.)&lt;/P&gt;&lt;P&gt;3	Complete Hierarchy&lt;/P&gt;&lt;P&gt;4	Subtree Below Nodes to (and Incl.) Level (Relative)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Imran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jul 2011 12:43:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/hierarchy-authorization/m-p/8096209#M1615928</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-07-11T12:43:35Z</dc:date>
    </item>
  </channel>
</rss>

