<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459449#M831168</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Pls. check below useful links.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With PDF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the below link,here you can see complete information about Auth checks and objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/a92195a9-0b01-0010-909c-f330ea4a585c" target="test_blank"&gt;https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/a92195a9-0b01-0010-909c-f330ea4a585c&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the below links.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nw04/helpdata/en/9f/dbaccb35c111d1829f0000e829fbfe/content.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw04/helpdata/en/9f/dbaccb35c111d1829f0000e829fbfe/content.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/9000821b-666a-2910-499a-aaffde140a9a" target="test_blank"&gt;https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/9000821b-666a-2910-499a-aaffde140a9a&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nw04s/helpdata/en/8d/3e4e19462a11d189000000e8323d3a/frameset.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw04s/helpdata/en/8d/3e4e19462a11d189000000e8323d3a/frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the below link for Main HR Authorization Object for Security .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.sap-img.com/human/main-hr-authorization-object-for-security.htm" target="test_blank"&gt;http://www.sap-img.com/human/main-hr-authorization-object-for-security.htm&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Feb 2008 03:14:21 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-02-15T03:14:21Z</dc:date>
    <item>
      <title>Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459448#M831167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is authorization check ,&lt;/P&gt;&lt;P&gt;how we can do that what is the purpose of authorization check pls give some help full infrmation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THX&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 03:05:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459448#M831167</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T03:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459449#M831168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Pls. check below useful links.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With PDF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the below link,here you can see complete information about Auth checks and objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/a92195a9-0b01-0010-909c-f330ea4a585c" target="test_blank"&gt;https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/a92195a9-0b01-0010-909c-f330ea4a585c&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the below links.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nw04/helpdata/en/9f/dbaccb35c111d1829f0000e829fbfe/content.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw04/helpdata/en/9f/dbaccb35c111d1829f0000e829fbfe/content.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/9000821b-666a-2910-499a-aaffde140a9a" target="test_blank"&gt;https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/9000821b-666a-2910-499a-aaffde140a9a&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nw04s/helpdata/en/8d/3e4e19462a11d189000000e8323d3a/frameset.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw04s/helpdata/en/8d/3e4e19462a11d189000000e8323d3a/frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the below link for Main HR Authorization Object for Security .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.sap-img.com/human/main-hr-authorization-object-for-security.htm" target="test_blank"&gt;http://www.sap-img.com/human/main-hr-authorization-object-for-security.htm&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 03:14:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459449#M831168</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T03:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459450#M831169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Authorization check is to restrict the access to a set of users ho have the authority to run the particular transaction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can just search help.sap.com for the detailed info on Authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Atish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 03:16:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459450#M831169</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T03:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459451#M831170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;authorization check mean checking the authorization of the user for a particular transaction. suppose a company wants to restrict the transaction XD02 i.e. change customer for a perticular user so that he can'nt change the customer details. so this is mainly to restrict the user for a perticular transaction etc. this authorization will be provide by basis or authorization team.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reward if helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Venkat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: venkata prasad on Feb 15, 2008 5:28 AM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 04:27:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459451#M831170</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T04:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459452#M831171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;usually authorization is not added on for one field in a table. if the user is not authorized to view the total field, then check the authority at the beginnning of the program. If the authority fails do not display the total field, else display the total field. There is no need to add authority check inside the loop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHORITY-CHECK OBJECT object&lt;/P&gt;&lt;P&gt;ID name1 FIELD f1&lt;/P&gt;&lt;P&gt;ID name2 FIELD f2&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;ID name10 FIELD f10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Effect&lt;/P&gt;&lt;P&gt;Explanation of IDs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object&lt;/P&gt;&lt;P&gt;Field which contains the name of the object for which the authorization is to be checked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name1 ...&lt;/P&gt;&lt;P&gt;Fields which contain the names of the&lt;/P&gt;&lt;P&gt;name10&lt;/P&gt;&lt;P&gt;authorization fields defined in the object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;f1 ...&lt;/P&gt;&lt;P&gt;Fields which contain the values for which the&lt;/P&gt;&lt;P&gt;f10&lt;/P&gt;&lt;P&gt;authorization is to be checked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHORITY-CHECK checks for one object whether the user has an authorization that contains all values of f (see SAP authorization concept).&lt;/P&gt;&lt;P&gt;You must specify all authorizations for an object and a also a value for each ID (or DUMMY).&lt;/P&gt;&lt;P&gt;The system checks the values for the IDs by AND-ing them together, i.e. all values must be part of an authorization assigned to the user.&lt;/P&gt;&lt;P&gt;If a user has several authorizations for an object, the values are OR-ed together. This means that if the CHECK finds all the specified values in one authorization, the user can proceed. Only if none of the authorizations for a user contains all the required values is the user rejected.&lt;/P&gt;&lt;P&gt;If the return code value in SY-SUBRC is 0, the user has the required authorization and may continue.&lt;/P&gt;&lt;P&gt;The return code value changes according to the different error scenarios. The return code values have the following meaning:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4&lt;/P&gt;&lt;P&gt;User has no authorization in the SAP System for such an action. If necessary, change the user master record.&lt;/P&gt;&lt;P&gt;8&lt;/P&gt;&lt;P&gt;Too many parameters (fields, values). Maximum allowed is 10.&lt;/P&gt;&lt;P&gt;12&lt;/P&gt;&lt;P&gt;Specified object not maintained in the user master record.&lt;/P&gt;&lt;P&gt;16&lt;/P&gt;&lt;P&gt;No profile entered in the user master record.&lt;/P&gt;&lt;P&gt;24&lt;/P&gt;&lt;P&gt;The field names of the check call do not match those of an authorization. Either the authorization or the call is incorrect.&lt;/P&gt;&lt;P&gt;28&lt;/P&gt;&lt;P&gt;Incorrect structure for user master record.&lt;/P&gt;&lt;P&gt;32&lt;/P&gt;&lt;P&gt;Incorrect structure for user master record.&lt;/P&gt;&lt;P&gt;36&lt;/P&gt;&lt;P&gt;Incorrect structure for user master record.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the return code value is 8 or 24, inform the person responsible for the program. If the return code value is 4, 12, 16 or 24, consult your system administrator if you think you should have the relevant authorization. In the case of errors 28 to 36, contact SAP because authorizations have probably been destroyed.&lt;/P&gt;&lt;P&gt;Individual authorizations are assigned to users in their respective user profiles, i.e. they are grouped together in profiles which are stored in the user master record.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note&lt;/P&gt;&lt;P&gt;Instead of ID name FIELD f, you can also write ID name DUMMY. This means that no check is performed for the field concerned.&lt;/P&gt;&lt;P&gt;The check can only be performed on CHAR fields. All other field types result in 'unauthorized'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;P&gt;Check whether the user is authorized for a particular plant. In this case, the following authorization object applies:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Table OBJ: Definition of authorization object&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M_EINF_WRK&lt;/P&gt;&lt;P&gt;ACTVT&lt;/P&gt;&lt;P&gt;WERKS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here, M_EINF_WRK is the object name, whilst ACTVT and WERKS are authorization fields. For example, a user with the authorizations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M_EINF_WRK_BERECH1&lt;/P&gt;&lt;P&gt;ACTVT 01-03&lt;/P&gt;&lt;P&gt;WERKS 0001-0003 .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can display and change plants within the Purchasing and Materials Management areas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Such a user would thus pass the checks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHORITY-CHECK OBJECT 'M_EINF_WRK'&lt;/P&gt;&lt;P&gt;ID 'WERKS' FIELD '0002'&lt;/P&gt;&lt;P&gt;ID 'ACTVT' FIELD '02'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHORITY-CHECK OBJECT 'M_EINF_WRK'&lt;/P&gt;&lt;P&gt;ID 'WERKS' DUMMY&lt;/P&gt;&lt;P&gt;ID 'ACTVT' FIELD '01':&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but would fail the check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHORITY-CHECK OBJECT 'M_EINF_WRK'&lt;/P&gt;&lt;P&gt;ID 'WERKS' FIELD '0005'&lt;/P&gt;&lt;P&gt;ID 'ACTVT' FIELD '04'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To suppress unnecessary authorization checks or to carry out checks before the user has entered all the values, use DUMMY - as in this example. You can confirm the authorization later with another AUTHORITY-CHECK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 04:29:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459452#M831171</guid>
      <dc:creator>former_member156446</dc:creator>
      <dc:date>2008-02-15T04:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459453#M831172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should carry out an authorization check before accessing the database. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The AUTHORITY-CHECK&lt;/P&gt;&lt;P&gt;statement first checks whether the user has the authorization containing all the required values. You then read the code value in the system field SY-SUBRC. If this value is 0, the user has the required authorization and the program can continue. If the value is not 0, the user does not possess the required authorization and the system outputs an appropriate message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The system administrator assigns user authorization when maintaining user master data. During this&lt;/P&gt;&lt;P&gt;process, you should determine exactly which data users are allowed to access and what kind of&lt;/P&gt;&lt;P&gt;access should be allowed. For example, you might want to allow users to display data for all airline&lt;/P&gt;&lt;P&gt;carriers, but only allow them to change data for certain selected ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authorization objects simply define the combination of fields that need to be addressed simultaneously&lt;/P&gt;&lt;P&gt;and serve as templates for both authorizations and authorization checks. They are organized into object&lt;/P&gt;&lt;P&gt;classes in order to make it easier to find and administer them; one object class or several may exist in&lt;/P&gt;&lt;P&gt;each application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When making authorization checks in programs, you specify the object and values the user needs in an&lt;/P&gt;&lt;P&gt;authorization to be able to access the object. You do not have to specify the name of the authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Authority-Check statement performs the authority check and returns an appropriate&lt;/P&gt;&lt;P&gt;return code value. When reading this return code, you can specify yourself the consequences of a&lt;/P&gt;&lt;P&gt;missing authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You must specify all fields of the object in an AUTHORITY-CHECK. Otherwise you receive a return&lt;/P&gt;&lt;P&gt;code not equal to zero. If you do not want to carry out a check for a particular field, enter DUMMY after&lt;/P&gt;&lt;P&gt;the field name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The most important return codes for AUTHORITY-CHECK are:&lt;/P&gt;&lt;P&gt;0: The user has an authorization containing the required values.&lt;/P&gt;&lt;P&gt;4: The user does not have the required authorization.&lt;/P&gt;&lt;P&gt;8: The check could not successfully be carried out since not all fields of the object were specified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;
REPORT sapbc400pbs_forms.
CONSTANTS actvt_display TYPE activ_auth VALUE '03'.
DATA: wa_flight TYPE sbc400focc,
it_flight TYPE sbc400_t_sbc400focc.
PARAMETERS: pa_car TYPE sflight-carrid.
DATA: returncode LIKE sy-subrc.
START-OF-SELECTION.
* Authority-Check:
PERFORM authority_scarrid USING pa_car actvt_display
CHANGING returncode.
CASE returncode.
* User is authorized
WHEN 0.
SELECT carrid connid fldate seatsmax seatsocc FROM sflight
INTO CORRESPONDING FIELDS OF wa_flight
WHERE carrid = pa_car.
wa_flight-percentage =
100 * wa_flight-seatsocc / wa_flight-seatsmax.
APPEND wa_flight TO it_flight.
ENDSELECT.
PERFORM write_list USING it_flight.

* User is not authorized or other error of authority-check
WHEN OTHERS.
WRITE: / 'Authority-Check Error'(001).
ENDCASE.

&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Hope this helps. Do reward&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Runal Singh on Feb 15, 2008 11:29 AM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 05:56:59 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459453#M831172</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T05:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459454#M831173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi chaya,&lt;/P&gt;&lt;P&gt;please see to the tutorioal below.&lt;/P&gt;&lt;P&gt;if useful reward points, and also add some commnets to the below link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[TUTORIAL|https://wiki.sdn.sap.com/wiki/display/Snippets/Concept&lt;EM&gt;of&lt;/EM&gt;Authorization&lt;EM&gt;For&lt;/EM&gt;users]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 06:05:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459454#M831173</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T06:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459455#M831174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls refer to the link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nw70/helpdata/en/52/671285439b11d1896f0000e8322d00/frameset.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw70/helpdata/en/52/671285439b11d1896f0000e8322d00/frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Renjith Michael.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.sourceveda.com/" target="test_blank"&gt;http://www.sourceveda.com/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 07:13:31 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459455#M831174</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T07:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459456#M831175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;EVERYHTING U NEED TO KNOW ABOUT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AUTHORIZATION CHECKS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should carry out an authorization check before accessing the database. The AUTHORITY-CHECK&lt;/P&gt;&lt;P&gt;statement first checks whether the user has the authorization containing all the required values. You&lt;/P&gt;&lt;P&gt;then read the code value in the system field SY-SUBRC. If this value is 0, the user has the required&lt;/P&gt;&lt;P&gt;authorization and the program can continue. If the value is not 0, the user does not possess the required&lt;/P&gt;&lt;P&gt;authorization and the system outputs an appropriate message.&lt;/P&gt;&lt;P&gt;Later in this course, you will learn how to make fields on the selection screen ready for input again if you&lt;/P&gt;&lt;P&gt;perform the authorization check right after the selection screen, and how to output a message if the user&lt;/P&gt;&lt;P&gt;does not have the required authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All data in the SAP system must be protected from unauthorized access by users who do not explicitly&lt;/P&gt;&lt;P&gt;have permission to access it.&lt;/P&gt;&lt;P&gt;The system administrator assigns user authorization when maintaining user master data. During this&lt;/P&gt;&lt;P&gt;process, you should determine exactly which data users are allowed to access and what kind of&lt;/P&gt;&lt;P&gt;access should be allowed. For example, you might want to allow users to display data for all airline&lt;/P&gt;&lt;P&gt;carriers, but only allow them to change data for certain selected ones. In this case, the system must look&lt;/P&gt;&lt;P&gt;for a combination of the fields 'activity' and 'airline carrier' each time it performs an authorization check.&lt;/P&gt;&lt;P&gt;Both fields must be filled with values during authorization creation as well (in this example, activity&lt;/P&gt;&lt;P&gt;'Change' and airline carrier 'LH' or activity 'Display' and airline carrier '*'). This is carried out by an&lt;/P&gt;&lt;P&gt;authorization object composed of the fields 'Activity' and 'Airline carrier' that has to be addressed both&lt;/P&gt;&lt;P&gt;during the authorization assignment process and whenever your program performs an authorization&lt;/P&gt;&lt;P&gt;check.&lt;/P&gt;&lt;P&gt;Authorization objects simply define the combination of fields that need to be addressed simultaneously&lt;/P&gt;&lt;P&gt;and serve as templates for both authorizations and authorization checks. They are organized into object&lt;/P&gt;&lt;P&gt;classes in order to make it easier to find and administer them; one object class or several may exist in&lt;/P&gt;&lt;P&gt;each application. You call the authorization object maintenance transaction from the 'Development'&lt;/P&gt;&lt;P&gt;menu in the ABAP Workbench. A complete list of all development objects, sorted according to class and&lt;/P&gt;&lt;P&gt;including their corresponding fields and documentation, is part of this transaction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When making authorization checks in programs, you specify the object and values the user needs in an&lt;/P&gt;&lt;P&gt;authorization to be able to access the object. You do not have to specify the name of the authorization.&lt;/P&gt;&lt;P&gt;The above example checks whether or not the user is authorized for the object S_CARRID, which has&lt;/P&gt;&lt;P&gt;the value 'LH' in the field CARRID (airline) and the value '02' for 'Change' in the field ACTVT (activity).&lt;/P&gt;&lt;P&gt;The abbreviations for the activities are documented in the tables TACT and TACTZ and also in the&lt;/P&gt;&lt;P&gt;appropriate objects.&lt;/P&gt;&lt;P&gt;Important: The Authority-Check statement performs the authority check and returns an appropriate&lt;/P&gt;&lt;P&gt;return code value. When reading this return code, you can specify yourself the consequences of a&lt;/P&gt;&lt;P&gt;missing authorization (for example, program terminates or skips some input lines).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHORITY-CHECK OBJECT 'S_CARRID'&lt;/P&gt;&lt;P&gt;ID CARRID FIELD '__________'&lt;/P&gt;&lt;P&gt;ID ACTVT FIELD '__________'.&lt;/P&gt;&lt;P&gt;IF SY-SUBRC NE 0.&lt;/P&gt;&lt;P&gt;ENDIF.&lt;/P&gt;&lt;P&gt;Inserting AUTHORITY-CHECK in Programs&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;AUTHORITY-CHECK&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;Insert statement&lt;/P&gt;&lt;P&gt;S_CARRID&lt;/P&gt;&lt;P&gt;Pattern&lt;/P&gt;&lt;P&gt;You insert&lt;/P&gt;&lt;P&gt;variables&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;System&lt;/P&gt;&lt;P&gt;generates&lt;/P&gt;&lt;P&gt;ABAP code&lt;/P&gt;&lt;P&gt;IF SY-SUBRC NE 0.&lt;/P&gt;&lt;P&gt;Process&lt;/P&gt;&lt;P&gt;return code&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You must specify all fields of the object in an AUTHORITY-CHECK. Otherwise you receive a return&lt;/P&gt;&lt;P&gt;code not equal to zero. If you do not want to carry out a check for a particular field, enter DUMMY after&lt;/P&gt;&lt;P&gt;the field name.&lt;/P&gt;&lt;P&gt;Example: When calling a transaction to change flight data, you should check whether or not the user is&lt;/P&gt;&lt;P&gt;authorized to change the entries for a particular airline carrier: AUTHORITY-CHECK&lt;/P&gt;&lt;P&gt;OBJECT 'S_CARRID' ID 'ACTVT' FIELD '02'&lt;/P&gt;&lt;P&gt;ID 'CARRID' DUMMY.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The most important return codes for AUTHORITY-CHECK are:&lt;/P&gt;&lt;P&gt;0:&lt;/P&gt;&lt;P&gt;The user has an authorization containing the required values.&lt;/P&gt;&lt;P&gt;4:&lt;/P&gt;&lt;P&gt;The user does not have the required authorization.&lt;/P&gt;&lt;P&gt;8:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The check could not successfully be carried out since not all fields of the object were specified.&lt;/P&gt;&lt;P&gt;For a complete list of return codes, refer to the keyword documentation for the AUTHORITY-CHECK&lt;/P&gt;&lt;P&gt;statement.&lt;/P&gt;&lt;P&gt;You can only specify a single field after the FIELD addition, not a selection table. There are function&lt;/P&gt;&lt;P&gt;modules which carry out the AUTHORITY-CHECK for all values in the selection table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;REWARD IF HELPFUL&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 07:37:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459456#M831175</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T07:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459457#M831176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AUTHORIZATION OBJECTS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SAP authorization concept, based on authorization Objects, has been realized to provide an understandable and simple procedure.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Several system elements which are to be protected form an authorization object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An authorization object allows complex tests of an Authorization for multiple conditions. &lt;/P&gt;&lt;P&gt;Authorizations allow users to execute actions within the system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An authorization object groups up to ten fields that related by AND.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For an authorization check to be successful, all field values of the authorization object must be maintained in the user master. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a transaction is called, a system program makes various checks to ensure that the user has the appropriate authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHORITY-CHECK checks whether a user has appropriate authorization. To do this, it searches in the specified authorization profile in the user master record to see whether the user has authorization for the authorization object specified in the command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the authorization is found and it contains the correct values, the check is successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A programmer wants to make an authorization check before bookings for business customers can be changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To do this, the programmer should create an authorization fields and assign for each field defined the value to be checked .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Authorization fields are created under Tools -&amp;gt; ABAP Workbench -&amp;gt; Development -&amp;gt;  Other tools -&amp;gt;  Authorization objects -&amp;gt; Fields .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SYNTAX: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AUTHORITY-CHECK OBJECT 'L_TCODE'&lt;/P&gt;&lt;P&gt;ID 'TCD' FIELD sy-tcode.&lt;/P&gt;&lt;P&gt;IF sy-subrc NE 0.&lt;/P&gt;&lt;P&gt;MESSAGE i010(zmsg) WITH sy-tcode.&lt;/P&gt;&lt;P&gt;LEAVE TO SCREEN 0.&lt;/P&gt;&lt;P&gt;ENDIF.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 07:45:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/authorization/m-p/3459457#M831176</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T07:45:21Z</dc:date>
    </item>
  </channel>
</rss>

