READ PROTECT not applying when report executed from Process

If you have questions or if you want to share your opinion about Aware IM post your message on this forum
Post Reply
karelh
Posts: 86
Joined: Wed Oct 26, 2016 10:20 pm

READ PROTECT not applying when report executed from Process

Post by karelh »

Hallo,

I have specific BO items that are protected from everyone EXCEPT Admin and System.

I have 2 reports in my system.
1. Print all items.
2. Print all items for a specific person.

When I log in as a normal user and print Report1 then none of the protected items are shown on the report BUT if I print Report2 then the protected items are shown on the report. The second report is not much different from the first except that the process starts with a "PICK FROM".

Interesting fact is that in the log the "PICK FROM" is shown as being executed by the LoggedInUser but the second part of the process shows no user.

I did however try to PROTECT it From All (no exception) but the result is still the same. The protection does work though because I cannot see the items in the queries or BO forms.

Anyone with any advice?
Last edited by karelh on Tue Jul 24, 2018 7:28 am, edited 1 time in total.
karelh
Posts: 86
Joined: Wed Oct 26, 2016 10:20 pm

Re: READ PROTECT NOT WORKING WITH 'PICK FROM'

Post by karelh »

Update...

After some more troubleshooting I came to the conclusion that the READ PROTECT is not working when I run a FIND, Query or anything from a process.

Can anyone else confirm the same behavior?
joben
Posts: 224
Joined: Wed Nov 06, 2019 9:49 pm
Location: Sweden
Contact:

Re: READ PROTECT not applying when report executed from Process

Post by joben »

I'm having the same issue with processes not caring about READ PROTECT when doing FIND, CLEAN, etc.

Currently building a system with multi-tenancy so security is really important.
READ PROTECT works great as long as processes are not involved.
Seems like processes run as system instead of LoggedInSystemUser, so basically they run with max privileges.

Am I missing something here? :D
Regards, Joakim

Image
Post Reply