AugForums.com

An Acumatica User Group

  • Free
    • Start Here
    • Rolodex
    • Podcast
    • Blog
    • Forums
  • Paid
    • AugSQL
    • GI Course
    • GI Library
    • Consulting
  • Register
Acumatica Forums

By using this website, you agree to our Terms of Use (click here)

Forums
AUG Forums
Everything Else
Reports Button Secu...
 
Notifications
Clear all

Questions Reports Button Security

 
Everything Else
Last Post by MichaelHansen 7 years ago
7 Posts
3 Users
1 Reactions
2,292 Views
RSS
MichaelHansen
Posts: 149
 MichaelHansen
Topic starter
April 19, 2019 11:41 am
(@michaelhansen)
Estimable Member
Joined: 6 years ago

I seem to be having issues with users not seeing the reports button on my Shipments screen. The thing that is throwing me off, is that they can get to all the reports under that button by searching them out. I assume there's more than just what's shown under access rights by screen for this (they have full access to Distribution, where Shipments and the related reports live), but I can't seem to find where I've managed to block them from using the "reports" button on the shipment screen itself.

Anyone play a lot with security who knows what I've broken?


6 Replies
MichaelHansen
Posts: 149
 MichaelHansen
Topic starter
April 19, 2019 5:59 pm
(@michaelhansen)
Estimable Member
Joined: 6 years ago

Well, according to my VARs, inheritance get's overridden by explicit denials, which caused our issue.

The users had two roles, the first granted permission to the entire "Distribution" module. The 2nd had fragmented permissions and explicitly denied the "reports" button.

If both are defined, you get the higher access, but if one is "inherited" you get denied access due to the explicit call for denial on the other role that has been set. It's not very intuitive, but it is something that is easily fixed. Next time, I think I'll just make unique roles for my users instead of combining multiple roles to avoid this scenario.


Reply
Royce Lithgo
Posts: 557
 Royce Lithgo
April 23, 2019 7:47 pm
(@roycelithgo)
Honorable Member
Joined: 6 years ago

I have this issue too and i am sure that its only a recent change that caused it. I have far too many roles and special cases for users to contemplate per user roles. I just have to be careful not to assign the same user 2 roles with overlapping access to the same object (where one role is restricted and the other unrestricted). It seems the restricted access role appears to have priority over the unrestricted one. So Acumatica is applying a "most restrictive" access rule when it comes to combining roles. This should be something configurable system wide if you ask me. I want to use a "least restrictive" rule for combining roles.


Reply
MichaelHansen
Posts: 149
 MichaelHansen
Topic starter
April 24, 2019 10:08 am
(@michaelhansen)
Estimable Member
Joined: 6 years ago

I 100% agree and it appears the "most restrictive vs least" isn't applied consistently. For example, my account has almost every single role on it and the admin role overrides most of them, unless the admin role is set via inheritance and another role isn't and explicitly says "no", then the "no" overrides my admin role.

It appears to me that:

If both roles are defined EXPLICITLY at the same level:
Higher Access Wins
(in my system, my Admin role has GRANTED for the finance module, Warehouse has REVOKED, I have both roles on and I get access)

If one role is INHERITED and one is EXPLICITLY defined at a specific level:
The EXPLICITLY defined role Wins
(This was my issue before: Warehouse was inheriting permissions that granted access to the whole module, but Data Entry was explicitly set to REVOKED, and the button was revoked for the user who had both assigned)

I don't like it and I'm not 100% sure I'm correct on all the settings, but at least I know not to expect "highest always wins" like in other platforms.


Reply
Tim Rodman
Posts: 3195
 Tim Rodman
Admin
May 5, 2019 7:36 pm
(@timrodman)
Famed Member
Joined: 10 years ago

I have noticed the same thing as you pointed out. "Explicit" access trumps "Inherited" access. Otherwise, higher level access wins.

It's especially annoying when you get into field level security. 


Reply
Royce Lithgo
Posts: 557
 Royce Lithgo
May 5, 2019 8:28 pm
(@roycelithgo)
Honorable Member
Joined: 6 years ago

So lets say on a page field I explicitly made it view only in 1 role and in another role the page inherited Delete access, then the view only access wins. This explains my issue. 

What if there were 2 roles with differing explicit access on the same field, which one wins then? If the higher level of access wins then it means in my inherited role i need to make explicit all properties that were restricted in my restricted role. Then when the 2 roles are combined, the inherited role should win over the restricted role (assuming the higher level of access wins when multiple explicit roles are combined on the same field).

 


Reply
MichaelHansen
Posts: 149
 MichaelHansen
Topic starter
May 6, 2019 10:24 am
(@michaelhansen)
Estimable Member
Joined: 6 years ago

@royce-lithgo That is the behavior I am seeing as I have that example running in my system. If two roles are EXPLICITLY defined, the highest appears to win. (Revoked vs Delete in my case, with delete taking precedence).


Reply
Tim Rodman reacted
Forum Jump:
  Previous Topic
Next Topic  
Forum Information
Recent Posts
Unread Posts
Tags
  • 12 Forums
  • 2,526 Topics
  • 10.9 K Posts
  • 12 Online
  • 2,411 Members
Our newest member: thollings
Latest Post: Generic inquiry with information from Audit history(CT301000)
Forum Icons: Forum contains no unread posts Forum contains unread posts
Topic Icons: Not Replied Replied Active Hot Sticky Unapproved Solved Private Closed

Online Members

 No online members at the moment

Acumatica Forums

Terms of Use & Disclaimers :: Privacy Policy

Copyright © 2025 · AUG Forums, LLC. All rights reserved. This website is not owned, affiliated with, or endorsed by Acumatica, Inc.

‹›×

    ‹›×