Quantcast
Channel: SCN: Message List - Security
Viewing all articles
Browse latest Browse all 5338

Re: Write access to Infotypes in the past

$
0
0

Hi Lars,

 

What does your structural profile look like exactly? Have you defined the period indicator (PDATE)?

I have a hard time figuring out whether time constraint "2" has anything to do with your issue.  It seems more likely that the cause for your issue is related to the user not being authorized for the employee in that specific period of time.

Does the custom infotype have the VALDT (access auth.) switch activated?  (You can check this in V_T582A for that infotype).

 

FYI, this is the F1 help on the VALDT field, which I think pertains to your issue:

 

To simplify matters, the term 'period of responsibility' will be used in the following. If, during a particular period, a person has one (or more) organizational assignment(s) for which the administrator is responsible according to his/her authorization profile, then we refer to the entire validity period of this(these) organizational assignment(s) as the 'period of responsibility'.

There are three different cases.

    1. The period of responsibility begins in the future.
    If the administrator has write authorization for the infotype/subtype, this is valid for all infotype records whose validity period is within the period of responsibility. Read authorization is valid for infotype records which do not extend beyond the end of the period of responsibility.
    2. The period of responsibility begins before the current date. Its end date is no more than a fixed number of days before the current date
    In this case, write or read authorization is valid in all periods. There are no time restrictions on the authorizations of the administrator for the relevant infotype records.
      The tolerance period enables the administrator to access infotype records that he/she was previously responsible for even if his period of responsibility has changed. You set up client-specific tolerance periods during the

HR: Authorization Main Switch

    transaction.
    3. The period of responsibility ends in the past. The end of the period of responsibility ends before the current date even if the tolerance period is taken into account.

In this case, the administrator does not have write authorization. Read authorization applies to infotype records which are not valid beyond the end of the period of responsibility.


Viewing all articles
Browse latest Browse all 5338

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>