Custom Role Security Issue – User Account API returns multiple Person IDs
I am facing an issue with a custom role derived from the standard Human Resource Specialist role.
When a user is assigned this custom role and uses the User Account REST API (/hcmRestApi/resources/11.13.18.05/userAccounts), the response returns multiple items (multiple Person IDs).
However, when the standard Human Resource Specialist role is assigned, the same API correctly returns only one Person ID, which is the desired behavior.
This issue appears to be related to security policies / data security in the custom role.
Has anyone faced a similar issue?
Which security privilege or data security policy could cause the API to return data for other users instead of only the logged-in user?
Tagged:
0