<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authorization and BDS in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-and-bds/m-p/10099387#M1814835</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're planning on using Business Document Services to store some documents. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is important that only specific roles have access to the document and the plan was to define our own BDS classname and add the authorization object S_BDS_DS (with the specific classname parameter) to the roles requiring access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, we see that a number of other roles already have the authorization object S_BDS_DS with classname='*'. This means that they'll also have access to the new documents which they shouldn't have. There are quite a few roles with this access, so it will not be possible to "clean them up". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We could limit the access to the program retriving the documents through the BDS BAPI, but user could always access transaction OAOR and bypass this additional check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any options for providing proper authorization in our case?&lt;/P&gt;&lt;P&gt;Are there alternatives to BDS that provide better security?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dagfinn Parnas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS BDS BAPI is in include LBDS_BAPIF01&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Feb 2014 08:53:11 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2014-02-19T08:53:11Z</dc:date>
    <item>
      <title>Authorization and BDS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-and-bds/m-p/10099387#M1814835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're planning on using Business Document Services to store some documents. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is important that only specific roles have access to the document and the plan was to define our own BDS classname and add the authorization object S_BDS_DS (with the specific classname parameter) to the roles requiring access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, we see that a number of other roles already have the authorization object S_BDS_DS with classname='*'. This means that they'll also have access to the new documents which they shouldn't have. There are quite a few roles with this access, so it will not be possible to "clean them up". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We could limit the access to the program retriving the documents through the BDS BAPI, but user could always access transaction OAOR and bypass this additional check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any options for providing proper authorization in our case?&lt;/P&gt;&lt;P&gt;Are there alternatives to BDS that provide better security?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dagfinn Parnas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS BDS BAPI is in include LBDS_BAPIF01&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Feb 2014 08:53:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-and-bds/m-p/10099387#M1814835</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-02-19T08:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization and BDS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-and-bds/m-p/10099388#M1814836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have used S_BDS_DS in the past so cleaning up the authorizations to not have * as CLASSNAME would be my first suggestion. Assuming the documents have a class set, you could try to use S_BDS_D since it seems to be used less frequently and especially not with * as LOIO_CLASS. I'm pinging the &lt;A __default_attr="2138" __jive_macro_name="community" class="jive_macro_community jive_macro" data-orig-content="SAP Document Management" href="https://community.sap.com/"&gt;&lt;/A&gt; space to involve DMS experts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Feb 2014 18:46:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization-and-bds/m-p/10099388#M1814836</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-02-19T18:46:11Z</dc:date>
    </item>
  </channel>
</rss>

