My Oracle Support Banner

After Saving Some Users Can Still Update the Price List Even Though Pricing Security is Set to View Only Privileges (Doc ID 2432554.1)

Last updated on AUGUST 13, 2018

Applies to:

Oracle Advanced Pricing - Version 11.5.10.2 and later
Information in this document applies to any platform.

Symptoms


ACTUAL BEHAVIOR
Finds that a newly created price list can be viewed and updated from any responsibility that has access to the same operating unit
for which the newly created price list resides.

EXPECTED BEHAVIOR
Expects same behavior as stated in the Advanced Pricing Implementation Manual states.

Oracle Advanced Pricing Implementation Guide, Release 12.1, Part Number E13428-04

"behavior while being created": Entity can be viewed and maintained by user who created it.
"after saving and exiting the entity setup window": All the users can view the new entity. But nobody can update it.


The issue can be reproduced at will with the following steps:
1. Ran “Security Control “ with parameter “ON”
    it set QP: Security Control = On

2. Set profile values

QP: Security Default Maintain Privilege = None
QP: Security Default ViewOnly Privilege = Global
--Verified via SQL profiles are only set at site level
--Per Advanced Pricing Implementation Manual states:
behavior while being created: Entity can be viewed and maintained by user who created it.
after saving and exitin the entity setup window: All the users can view the new entity. But nobody can update it.



Site settings:
  MO: Default Operating Unit = NULL
  MO: Operating Unit = S&C CHICAGO SALES
  MO: Security Profile = NULL


Responsibility (OM AUS USER) settings:
  MO: Default Operating Unit = NULL
  MO: Operating Unit = S&C AUSTRALIA
  MO: Security Profile = NULL


Responsibility (OM AUS SUPERUSER) settings:
  MO: Default Operating Unit = NULL
  MO: Operating Unit = S&C AUSTRALIA
  MO: Security Profile = NULL



Responsibility (OM TORONTO USER) settings:
  MO: Default Operating Unit = NULL
  MO: Operating Unit = S&C TORONTO
  MO: Security Profile = NULL



3. Logged in as a newly created user pricing1

4. From OM AUS USER, created a new price list “DY SR TEST1” with Global flag = Yes and saved.

5. Switched to OM TORONTO USER responsibility, opened the price. It’s view only. Same as expected.

6. Switched to OM AUS SUPERUSER. This price list can be updated. Expected view only

7. Switched to OM AUS USER. This price list can be updated. Expecting view only

8. Logged in as newly created user pricing2:

9. From OM TORONTO USER responsibility, opened the price. It’s view only. Same as expected.

10. Switched to OM AUS USER. This price list can be updated. Expecting view only.

11. Switched to OM AUS SUPERUSER. This price list can be updated. Expecting view

12. Reviewed privileges assigned to this price list.
  Logged in and went to Oracle Pricing Administrator responsibility,
  searched privilege by price list
  find it is set at Global to view only.


Changes

 

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.