Kbase P78781: Dynamics. Cannot override group restrictions for individual user
Autor |
  Progress Software Corporation - Progress |
Acesso |
  Público |
Publicação |
  11/3/2009 |
|
Status: Unverified
SYMPTOM(s):
Dynamics. Cannot override group restrictions for individual user
FACT(s) (Environment):
Dynamics 2.1A
Dynamics OE 10
CHANGE:
Security mode: Revoke
When a user is allocated to a security group, it should be possible to override
specific restrictions that are set for the group, at the user level. The security
control UI does not provide a way of doing this.
Example:
User ugTest belongs to group gTest.
Group gTest has Action restrictions on 'Add' and 'Delete'
We want to override the restriction on 'Add' for user ugTest
Steps to reproduce:
-------------------
1. Create security group: gTest
2. Create user: ugTest
3. Allocate user ugTest to group gTest
4. Under Security Allocations, select: Actions
5. Enter Name = gTest
6. Press 'Refresh'
7. Move Add (all) and Copy (all) to the Restricted Actions list
8. Save
9. Enter Name = ugTest
10. Press 'Refresh'
11. Note that the Restricted Actions list is empty.
12. There is no way of un-allocating the 'Add' restriction for user ugTest on this
screen
13. Go to Security Enquiry --> Actions
14. Enter Name = ugTest
15. Press 'Refresh'
16. Select 'Secured Only' in the radio-set at the top of the Details tab
17. Note that 'Add' and 'Delete' are both listed as 'Revoked group gTest'
18. There is no way of overriding the 'Add' restriction on this screen either
CAUSE:
When security is allocated against users, with the exception of field and range
security, the administrator must now specify whether the security object being
allocated is secured or not. The default "secured" value is YES.
To document:
-------------
All security allocation UIs are affected with the exception of field and data range
security. They have not changed in any way and will keep on working as they
always have.
For the rest:
- When security is being allocated at user level, a radio set is displayed where the administrator can select if the object is secured or not. In the allocated security browser, an updatable browse column with a label of "Secured" has also been added. Multiple browse lines can be selected and updated to the value in the radio set by pressing the "Apply" button. The administrator can then specify
whether objects are secured or not at user level. The security assigned here will always override security set up at group level.
- When security is being allocated for a security group, the two security allocation browsers are displayed. The administrator allocates security as needed and depending on the security model the allocated security will be either granted or revoked for users belonging to the group.
FIX:
None at this time