<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization object S_DATASET in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140810#M1620253</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ashish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, He will get the merged Authorizations for his access !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During authorization check, Authorization fields are always checked in an AND relationship for each authorization object instance within role(s).&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Raichand&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Sep 2011 18:06:14 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2011-09-16T18:06:14Z</dc:date>
    <item>
      <title>Authorization object S_DATASET</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140808#M1620251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question..(may be silly one &lt;SPAN __jive_emoticon_name="grin"&gt;&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i have a auth object say S_DATASET available in 2 roles with different values.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S_DATASET&lt;/P&gt;&lt;P&gt;Activity                                          33, 34                                                                   ACTVT&lt;/P&gt;&lt;P&gt;Physical file name                         /transfer/C11/order/aus                                       FILENAME&lt;/P&gt;&lt;P&gt;Program Name with Search Help  *                                                                           PROGRAM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S_DATASET&lt;/P&gt;&lt;P&gt;Activity                       33, 34, A6, A7                                                              ACTVT&lt;/P&gt;&lt;P&gt;Physical file name             *                                                                           FILENAME&lt;/P&gt;&lt;P&gt;Program Name with Search Help  ZP1, ZP2, ZP3                                   PROGRAM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now what happens when both roles are assigned to a single user. Does he get S_DATASET with activity merged ?? means will he have auth lieke this :&lt;/P&gt;&lt;P&gt;S_DATASET&lt;/P&gt;&lt;P&gt;Activity                                          33, 34, A6, A7                                                     ACTVT&lt;/P&gt;&lt;P&gt;Physical file name                         *                                                                           FILENAME&lt;/P&gt;&lt;P&gt;Program Name with Search Help  *                                                                           PROGRAM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;ashish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 12:45:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140808#M1620251</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-09-16T12:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization object S_DATASET</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140809#M1620252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nope, authorizations do not merge.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 13:03:25 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140809#M1620252</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2011-09-16T13:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization object S_DATASET</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140810#M1620253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ashish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, He will get the merged Authorizations for his access !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During authorization check, Authorization fields are always checked in an AND relationship for each authorization object instance within role(s).&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Raichand&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 18:06:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140810#M1620253</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-09-16T18:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization object S_DATASET</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140811#M1620254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From an academic perspective they could however be merged by program ZP1, ZP2 or ZP3 using actvt A7, because this permits operating system commands to any file system location. At the operating system level you could then do almost anything (such as merging the two roles into one in a transport request, adding it to the tp buffer and importing it).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your first priorities should be to restrict the program name and the A* actvties and maintain su24 with the; then restrict / validate what the programs are capable of doing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 18:10:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140811#M1620254</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-09-16T18:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization object S_DATASET</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140812#M1620255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: ashish vikas on Sep 16, 2011 8:12 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 18:11:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140812#M1620255</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-09-16T18:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization object S_DATASET</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140813#M1620256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jurjen Heeck is correct, but Actvt A7 with program * is critical for the operating system. Not a good idea and seldom needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 18:17:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140813#M1620256</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-09-16T18:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization object S_DATASET</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140814#M1620257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but in Role 2, I am not giving * for Program. it has only 3 programs ZP1, ZP2, ZP3 with Activity A7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;ashish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 18:22:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140814#M1620257</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-09-16T18:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization object S_DATASET</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140815#M1620258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you are correct, but it does depend on what those 3 programs do and which import parameters / selection screens they have. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why do you want to put * into the program name of the first role though?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the user create a file in the order directory with the name permitted, then use ZP1 to move it to a different directory and rename it and execute it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The mix seems suspect to me because of the combined access from building roles using different techniques, but they are not merged!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 18:33:18 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140815#M1620258</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-09-16T18:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization object S_DATASET</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140816#M1620259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wait, to be clear....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason why "auths don't merge" in OP's case... is because ACTVT, FILENAME, and PROGRAM are unique in the two profiles, correct?   But if the situation was like below instead, then you could think about it as "auths merging" even though technically that doesn't happen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so if it was:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S_DATASET&lt;/P&gt;&lt;P&gt;Activity 33, 34 ACTVT&lt;/P&gt;&lt;P&gt;Physical file name /transfer/C11/order/aus FILENAME&lt;/P&gt;&lt;P&gt;Program Name with Search Help ZP1, ZP2, ZP3 PROGRAM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S_DATASET&lt;/P&gt;&lt;P&gt;Activity 33, 34  ACTVT&lt;/P&gt;&lt;P&gt;Physical file name * FILENAME&lt;/P&gt;&lt;P&gt;Program Name with Search Help ZP1, ZP2, ZP3 PROGRAM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then the FILENAME restriction from 1st role would be ignored because of the * in the 2nd role.   But if we added ACTVT A6 to the 1st role, then this role would not be overriden the 2en, because the auths don't match, meaning in this case, the user would have ACTVT A6 for filename transfer/C11/order/aus  and nothing else.   Correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Sep 2011 19:02:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140816#M1620259</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-09-30T19:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization object S_DATASET</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140817#M1620260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having added A6 would have kept the merge appart, but that is no reason to keep the merge appart from a cosmetic perspective. The access is the same if all other fields are identical.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I sometimes use "banana" values to avoid merging so that I can later keep them appart. But this is only because there is not unmerge function to split them appart again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you could achieve actvt A6 for the first authorization's other fields by adding it first, but if A6 is not needed then it would add not value...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;gt; ZP1, ZP2 etc will anyway read and write to /TRANSFER/C11/...  etc and does not need A6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But okay, they are two seperate authorization instances assigned to the same user and they look different.... if that is your goal  &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using transaction FILE and SPTH you could however achieve more granularity (beyond the "file name"),&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Sep 2011 22:37:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-object-s-dataset/m-p/8140817#M1620260</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-09-30T22:37:05Z</dc:date>
    </item>
  </channel>
</rss>

