Role Based Security Is Not Working For Change Order UDA (Doc ID 2096943.1)

Last updated on JANUARY 20, 2016

Applies to:

Oracle Product Hub - Version 12.2.4 and later
Information in this document applies to any platform.

Symptoms

Actual Behavior
Role Based security is not working for Change Order UDA.
We defined a privilege and associated to attribute group of change order object.
It is allowing user to update attribute group without assigning a role on the change order

Expected Behavior
User should not be able to update the attribute group unless they have the proper role.

Steps to Reproduce

1. log as sysadmin, Application Developer > Application > Function, create Function CHANGE_UDAT_EDIT
    Properties tab, Type = Subfunction
    Region tab, Object = Change
    
2. log as plmmgr, Development Manager > Setup > Setup Workbench > Change Management tab > Header Attributes sub-tab,
    create change header AG Change_Test, In business entities: add Edit privilege: CHANGE_UDA_EDIT, add two attributes
    
3. Create a change order type JE_UDA_EDIT by duplicated from existing CO type ADCO
    Add AG Change_Test
    Create page Change_Test to associate above AG
    
4. Item Catalog > Create Production Item, create item JE2016011401
    
5. In the item overview page, Action = Create Change Order, select CO type = JE_UDA_EDIT
    
6. Navigate to Change_Test link, update the UDA, can be done.
    
7. Go to the Change Test link from item overview page, can be done.

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms