Login
Register
Search
Home
Forums
Jobs
LawsonGuru
LawsonGuru Letter
LawsonGuru Blog
Worthwhile Reading
Infor Lawson News Feed
Store
Store FAQs
About
Forums
Infor / Lawson Platforms
S3 Security
Need help troubleshooting a rule
Home
Forums
Jobs
LawsonGuru
LawsonGuru Letter
LawsonGuru Blog
Worthwhile Reading
Infor Lawson News Feed
Store
Store FAQs
About
Who's On?
Membership:
Latest:
Jeffin Joy
Past 24 Hours:
0
Prev. 24 Hours:
0
Overall:
4988
People Online:
Visitors:
42
Members:
0
Total:
42
Online Now:
New Topics
Top Forum Posters
Name
Points
Greg Moeller
4184
David Williams
3349
Kat V
2984
Woozy
1973
Jimmy Chiu
1883
Kwane McNeal
1437
Ragu Raghavan
1377
Roger French
1315
mark.cook
1244
Chris Martin
825
Forums
Filtered Topics
Unanswered
Unresolved
Active Topics
Most Liked
Most Replies
Search Forums
Advanced Search
Prev
Next
Forums
Infor / Lawson Platforms
S3 Security
Need help troubleshooting a rule
Please
login
to post a reply.
1 Replies
0
Subscribed to this topic
19 Subscribed to this forum
Sort:
Oldest First
Most Recent First
Author
Messages
John Costa
Veteran Member
Posts: 154
5/9/2012 6:16 PM
To all,
I need help understanding / troubleshooting a unique security issue.
In our LDAP schema, we've defined a custom attribute named Region. This attribute is defined as a 15-character string. The values are limited to the following:
CMS-HR
Corporate-HR
Cypress-HR
Manasquan-HR
Region-SW
Wichita-HR
In the Lawson Security Administrator, this Region attribute is then set for each employee in their RM record.
We are licensed for Employee Self-Service, LP - Absence Management, and TA - Event Management. In 2010, we converted from TA to LP. Since then, all employee Leave Balances are tracked in the LP module.
Here's where it gets interesting. I have a security class that is assigned to specifc HR employees. The purpose of this class is to limit the data those employees can see based on the Region attribute in their RM record. The rule for that class is as follows:
if(SystemCode=='AC')||isStructNodeTitleAbove('ClassDataStructure',PROCESS_LEVEL,user.getAttribute('Region'))){'ALL_ACCESS.'}else{'NO_ACCESS,'}
For some reason, any HR employee that has this class assigned to their role sees their PTO balance as it existed in the TA module at the time of the conversion. If I remove this class from their role, they then see their PTO balance as it currently exists in the LP module.
Can someone help me out in understanding why this rule limits Leave Balance access to the old information in the TA module and not the current information in the LP module?
John Henley
Posts: 3366
New Poster
Congrats on posting!
Engaged Reader
You are an engaged reader!
Avid Reader
Avid Reader art thou!
5/9/2012 6:46 PM
Split
John,
Usually when I see that happen it is because the class has a securable object type (i.e. table or form) combined with a given system code/category. That combination results in all tables/forms being available for the entire system code. That would be the first thing I'd look at. See this article:
https://www.lawsonguru.co...cation-Security.aspx
Please
login
to post a reply.