Limited User Role Can Unmerge Records Without Permission
Last updated on AUGUST 25, 2016
Applies to:Oracle Healthcare Master Person Index - Version 3.0.0 to 4.0 [Release 3.0 to 4.0]
Information in this document applies to any platform.
On : 3.0.0 and 4.0.0 versions, Master Index Main Component
Users having attached a role without 'EO_Unmerge' operation are still able to access the 'Unmerge' buttons and are able to unmerge a record.
The 'Unmerge' buttons should be hidden and the Unmerge operation should be suppressed for this role.
The issue can be reproduced at will with the following steps:
1. Login to MIDM as admin and merge 2 existent records
2. Login as a limited user - without 'EO_Unmerge' operation
3. Go to Record Details > Simple Patient Lookup (EUID): 0000000XXX > View Merge Tree > Preview Unmerge > Unmerge – EUID 0000000XXX : Unmerge Successful
Some limited roles should definitely not be allowed to unmerge records.
The customers need to make sure that the Unmerge operation is not allowed in case a user tries it intentionally or unintentionally.
Sign In with your My Oracle Support account
Don't have a My Oracle Support account? Click to get started
Million Knowledge Articles and hundreds of Community platforms