08-26-2008 12:38 AM
Hi,
We have a role that was assigned to a user temporarily so that he can perform certain functions. When it was removed, we noticed that the user can still access those transactions that were previously granted even after several relogins over a period of 1 hour.
In other words, he can still access those transactions after relogging in an hour later !
The ID was removed from the role via PFCG, and user comparison done. From PFCG, that ID is not there anymore. From SU01, the role/profile is also not there.
We can use PFUD to clear it but would like to know what could have caused this.
Has anyone ever encountered this before? How was it resolved (besides using PFUD)?
Thanks in advance !
08-26-2008 5:47 AM
Hi Sisab,
did you set auth/new_buffering to 4 already (standard in actual release)?
PFUD/usercomparison works without problems normally. Pls check userbuffer content after removal or the role assignement and user comparison.
The expirience shows, that such cases may be caused by problems with buffer synchronization between different aplication servers. So first make sure, that the entries are removed on the database itself (usrbf2), then check the content on your other servers (if you have such...).
The FM susr_user_buffer_after_change should resolve the issue immediately (option 'profile' should be 4 when executing. There have been some corrections regarding buffering of user tables, pls make sure, that you have all of them implemented already.
b.rgds, Bernhard
08-26-2008 5:47 AM
Hi Sisab,
did you set auth/new_buffering to 4 already (standard in actual release)?
PFUD/usercomparison works without problems normally. Pls check userbuffer content after removal or the role assignement and user comparison.
The expirience shows, that such cases may be caused by problems with buffer synchronization between different aplication servers. So first make sure, that the entries are removed on the database itself (usrbf2), then check the content on your other servers (if you have such...).
The FM susr_user_buffer_after_change should resolve the issue immediately (option 'profile' should be 4 when executing. There have been some corrections regarding buffering of user tables, pls make sure, that you have all of them implemented already.
b.rgds, Bernhard
08-26-2008 7:07 AM