SAP Knowledge Base Article - Public

2592635 - Custom navigation - Able to access custom menu without permission

Symptom

  • We have a custom menu named 'LinkedIn' in our instance and we have configured it as 'Top Navigation' in 'Configure Custom Navigation' page.
  • This menu should not be displayed if a user does not have permission to access it.
  • However, users who are not included in the permission group that allows to access this menu can still access the menu 'LinkedIn' when they are on Configure Custom Navigation page.

Environment

SAP SuccessFactors Bizx Platform

Reproducing the Issue

  • Create a custom menu called 'LinkedIn' as top navigation in 'Configure custom navigation' page and assign a permission group.

       LinkedIn.PNG

  • User who doesn't belong to the permission group assigned for custom menu 'LinkedIn' logs in to the instance and clicks Home in Top Navigation to show drop down menu. 'LinkedIn' is not displayed in the list.

        cannot find it from home.PNG

  • User goes to 'Configure Custom Navigation' page and clicks Home in Top Navigation.
  • It shows 'LinkedIn' in the list (This menu should not be displayed because user does not have permission to access this menu).

       Able to view.PNG

  • User clicks on 'LinkedIn' in Top Navigation. The LinkedIn page opens.

Cause

  • If the admin user is allowed to configure the configuration in the "Configure Custom Navigation" page, then while they are on that page, they will be seeing all custom menu items in the Top Navigation, regardless of whether they have permission to view it or not.
  • The reason for this is because, the admin user who has "Manage Role-Based Permission Access" needs to be able to see all custom menu items to be able to configure them on the "Configure Custom Navigation" page, and it is the last state of the custom menu items that are currently shown in the Top Navigation when the user is currently on the "Configure Custom Navigation" page.
  • If the user goes to some other page, then they should correctly see only the custom menu items in the Top Navigation that they are currently configured the permission to see.

Resolution

  • This is an expected behaviour as described in the cause above.

See Also

  • KBA 2373626 - Enable Configure Custom Navigations and grant permission
  • KBA 2195722 - Adding Custom Navigation Actions

Keywords

Custom navigation, able to view custom menu without permission, custom menu, permission for custom navigation, top navigation, menu item lables, home drop down, permission. , KBA , LOD-SF-PLT-NAV , Custom Navigation , LOD-SF-PLT , Platform Foundational Capabilities , Problem

Product

SAP SuccessFactors HCM Core 1711 ; SAP SuccessFactors Platform all versions