Quantcast
Channel: SCN: Message List - Security
Viewing all articles
Browse latest Browse all 5338

Re: Determining Proper Authority Checks for Custom Transactions

$
0
0

Hi Akshay,

 

The authorisation checks that you build into the new reports should be based on the requirements for possible data access restrictions and/or ensuring secure controls to specific data that is being viewed in that report.  A high level example might be if the report is showing information that would be found in a financial document then the user should have the appropriate authorisations to view those accounting documents. If they should only be able to see accounting documents for company code 1000 then you can include an authority check for the authorisation object F_BKPF_BUK and restrict the access within the roles to the the necessary company codes.

 

A good place to start might be to look at the authorisation checks that are proposed for similar transactions. You can check these proposals through SU24 and also add them to your custom transactions with predefined values where necessary.


Viewing all articles
Browse latest Browse all 5338

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>