Classic Contract UI bypassing Access Group Object Rules despite removing DSPs from Custom Roles
Summary:
Classic Manage Contract UI bypassing Access Group Object Rules for Contracts despite removing DSPs from Custom Roles
Content (please ensure you mask any confidential information):
We are implementing "Control Access to Contracts Using Access Groups" to restrict users to only view contracts with specific Contract Type.
While the security works perfectly in the Redwood UI, the Classic "Manage Contracts" page ignores the Object Rules entirely, allowing the user to view all contracts.
Our Configuration following oracle doc
:
Created Custom Job/Duty roles (Deep Copy).
Removed all "Grant on Contract" DSPs.
Added ORA_ZCA_ACCESS_GROUPS_ENABLEMENT_DUTY.
Ran all required ESS Jobs (LDAP, Update Groups, Publish Rules, Object Sharing Assignment).
0