SAP Knowledge Base Article - Public

3543743 - Users are able to edit stories without permissions in SAP Analytics Cloud (SAC)

Symptom

Users are able to edit stories while they are shared with View only access.

Environment

SAP Analytics Cloud Enterprise

Reproducing the Issue

  1. Login to SAC with custom role assigned.
  2. Open a story (shared with View Access only).
  3. User is able to edit the story, while they should not have the access to edit it.

Cause

The custom role assigned to the user has Manage permission on Public and Private files.

Resolution

Removing the Manage permissions on Public Folders in the custom roles resolves the issue and the users won't be able to have full privileges on the shared content to them.

Reference:  SAP Analytics Cloud Help - Permissions where it is mentioned:  If a user has the Manage permission for a content space, and the user opens a file from that space, the user's rights are upgraded to full privileges. Example: Let's say a user shares a story with you with only read rights. However, this story is stored in the Public folder, and you have Manage rights on Public Files. If you open the story, your rights are automatically updated to full privileges.

See Also

Your feedback is important to help us improve our knowledge base.

Keywords

SAC, SAP Analytics Cloud, permissions, roles, user, users, edit, access, privileges, manage, public, private, files, custom, role, administration, team, teams , KBA , LOD-ANA-ADM , SAC Administration , Problem

Product

SAP Analytics Cloud 1.0