Quantcast
Channel: SCN : Discussion List - Security
Viewing all articles
Browse latest Browse all 2353

Restrict user to display only in VK13

$
0
0

I have a requirement in which a user should have the following access:

 

  • VK13 - display access on all condition types
  • VV11, VV12, VV21, VV22, VV71, VV72, VV31, and VV32 - Create and Change condition types Z123 and Z124 for output billing, shipping, sales, and transportation

 

Based on the above scenario, I've configured the below authorizations for actvity and condition type:

V_KONH_VKS - Condition: Authorization for Condition Types (03; *)

V_KONH_VKS - Condition: Authorization for Condition Types (01, 02; Z123 and Z124)

 

V_KONH_VKO - Condition: Authorization for Sales Organizations (01, 02, 03)

 

Based on this, the user should be able to maintain only  Z123 and Z124 condition types.  When I user goes to VK13 to display a ZXXX condition type, the user can then click on the change icon and update this condition type even though the user isn't authorized in the roles. 


I've used ST01 to trace the user and the check in happening first on the V_KONH_VKO authorization object and it's not checking the V_KONH_VKS authorization activities as it should. 

 

 

 

Can someone please help?  Is there a way to restrict this with standard authorizations?   if not, please provide your recommendations.


Viewing all articles
Browse latest Browse all 2353

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>