Symptom
After adding catalog SAP_CORE_BC_EXT to a Business Role and setting read only restrictions, the users with this business role assigned has full access to the extensibility apps.
Environment
SAP S/4HANA Cloud Public Edition 1908
Cause
The following catalogs are part of an exception list for which R/W restrictions are not supported:
- SAP_CORE_BC_EXT
- SAP_FIN_BC_GL_AUDIT_PC
- SAP_CORE_BC_EXT_TEST
- SAP_CORE_BC_SL_ETM
- SAP_CORE_BC_SL_EXP
- SAP_CORE_BC_SL_IMP
- SAP_CORE_BC_SEC
Resolution
It is not possible to differentiate between the read only access and read-and-write access. If the business catalog SAP_CORE_BC_EXT has been assigned to a business role, a user with this business role has the full access to the app.
Keywords
"Custom Business Objects" "Custom Catalog Extensions" "Custom CDS Views" "Custom Communication Scenarios" "Custom Fields and Logic" "Custom Logic Tracing" "Custom Reusable Elements" "Custom Tiles" "Extensibility Inventory" "SAP_BR_ADMINISTRATOR" , KBA , BC-SRV-APS-IAM , Identity and Access Management , Problem