Application Development and Automation Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Authority-check

Former Member
0 Likes
1,845

Hi,

What is the use of this authority check.I want to find the authority-check object for field lgnum(warehouse).In which table can I find this?

Hi,

What is the use of this authority check.I want to find the authority-check object for field lgnum(warehouse).In which table can I find this?

5 REPLIES 5
Read only

Former Member
0 Likes
1,083

U can check in

SU21 transaction code.

Regards

Jagadeeshwar.B

Read only

bpawanchand
Active Contributor
0 Likes
1,083

Hi

To ensure that a user has the appropriate authorizations when he or she performs an action, users are subject to authorization checks.

http://help.sap.com/saphelp_nw70/helpdata/en/52/67167f439b11d1896f0000e8322d00/frameset.htm

Regards

Pavan

Read only

Former Member
0 Likes
1,083

go to SE16 and give AGR_1251 and give the *object name.

you will get Authority objects for that object.

L_LGNUM

L_BWLVS

M_IS_LGNUM

M_MATE_LGN

W_APPT

Regards,

Rajasekhar Reddy

Read only

Former Member
0 Likes
1,083

Hi hema,

USE OF AUTHORITY CHECK:

Authorization checks are triggered by the ABAP

AUTHORITY-CHECK statement. The

programmer specifies an authorization object and the

required values for each authorization

field. The AUTHORITY-CHECK then verifies if a user has

authorization and if this

authorization is from the user master record. The

check is successful if an authorization is

found that contains the values specified in the

AUTHORITY-CHECK.

Basic form

AUTHORITY-CHECK OBJECT object

ID name1 FIELD f1

ID name2 FIELD f2

...

ID name10 FIELD f10.

Effect

Explanation of IDs:

object Field which contains the name of the object for which the authorization is to be checked.

name1 ... Fields which contain the names of the name10 authorization fields defined in the object.

f1 ... Fields which contain the values for which the f10 authorization is to be checked.

AUTHORITY-CHECK checks for one object whether the user has an authorization that contains all values of f (see SAP authorization concept).

You must specify all authorizations for an object and a also a value for each ID (or DUMMY ).

The system checks the values for the ID s by AND-ing them together, i.e. all values must be part of an authorization assigned to the user.

If a user has several authorizations for an object, the values are OR-ed together. This means that if the CHECK finds all the specified values in one authorization, the user can proceed. Only if none of the authorizations for a user contains all the required values is the user rejected.

If the return code SY-SUBRC = 0, the user has the required authorization and may continue.

The return code is modified to suit the different error scenarios. The return code values have the following meaning:

4 User has no authorization in the SAP System for such an action. If necessary, change the user master record.

8 Too many parameters (fields, values). Maximum allowed is 10.

12 Specified object not maintained in the user master record.

16 No profile entered in the user master record.

24 The field names of the check call do not match those of an authorization. Either the authorization or the call is incorrect.

28 Incorrect structure for user master record.

32 Incorrect structure for user master record.

36 Incorrect structure for user master record.

If the return code value is 8 or possibly 24, inform the person responsible for the program. If the return code value is 4, 12, 15 or 24, consult your system administrator if you think you should have the relevant authorization. In the case of errors 28 to 36, contact SAP, since authorizations have probably been destroyed.

Individual authorizations are assigned to users in their respective user profiles, i.e. they are grouped together in profiles which are stored in the user master record.

Instead of ID name FIELD f , you can also write ID name DUMMY . This means that no check is performed for the field concerned.

The check can only be performed on CHAR fields. All other field types result in 'unauthorized'.

Example

Check whether the user is authorized for a particular plant. In this case, the following authorization object applies:

Table OBJ : Definition of authorization object

M_EINF_WRK

ACTVT

WERKS

Here, M_EINF_WRK is the object name, whilst ACTVT and WERKS are authorization fields. For example, a user with the authorizations

M_EINF_WRK_BERECH1

ACTVT 01-03

WERKS 0001-0003 .

can display and change plants within the Purchasing and Materials Management areas.

Such a user would thus pass the checks

<![if !supportEmptyParas]> <![endif]>AUTHORITY-CHECK OBJECT 'M_EINF_WRK' ID 'WERKS' FIELD '0002' ID 'ACTVT' FIELD '02'.<![if !supportEmptyParas]> <![endif]>AUTHORITY-CHECK OBJECT 'M_EINF_WRK' ID 'WERKS' DUMMY ID 'ACTVT' FIELD '01':but would fail the check

<![if !supportEmptyParas]> <![endif]>AUTHORITY-CHECK OBJECT 'M_EINF_WRK' ID 'WERKS' FIELD '0005' ID 'ACTVT' FIELD '04'.

To suppress unnecessary authorization checks or to carry out checks before the user has entered all the values, use DUMMY - as in this example. You can confirm the authorization later with another AUTHORITY-CHECK .

Transaction code : SU21

Regards,

Sravanthi

Read only

Former Member
0 Likes
1,083

Hi Hema,

AUthory check is nothing but the authorization created for specific user or restrictions for users to particular transactions etc.....e.g. I can not access SU21 trasanction on client SAP system because I am not authorizaed to view the same.

Ok....For this you need to -->

1. GO to SU21.

2. Create Object Class first.

3. Create Authorization Object and assign the class to the same.

4. While creating the Object you need to provide the fields for which you need authorization.

5. First provide field ACTVT and then your fieldname.

6. Save and Activate....

In your Program call FM 'AUTHORITY_CHECK' ...

lv_field1 = tbl_upload-ekorg.

lv_field2 = tbl_upload-werks.

*Authority check for Pur Org and Plant

CALL FUNCTION 'AUTHORITY_CHECK'

EXPORTING

USER = SY-UNAME

OBJECT = 'ZM02'

FIELD1 = lv_field1

field2 = lv_field2

EXCEPTIONS

USER_DONT_EXIST = 1

USER_IS_AUTHORIZED = 2

USER_NOT_AUTHORIZED = 3

USER_IS_LOCKED = 4

OTHERS = 5.

<removed_by_moderator>

Edited by: Julius Bussche on Jul 9, 2008 2:03 PM