SAP Knowledge Base Article - Preview

3792245 - Data Access Controls Not Working After User Attribute Trimming Fix

Symptom

After upgrading to version 2026.19, customers report that their Data Access Controls (DAC) are no longer working as expected. Specifically:

  • Users who previously had access to data based on permission entities are now unable to access that data;
  • Permission entities that were working before the upgrade now fail to match users' attributes;
  • The issue affects permission entities that use IDP custom attributes (custom1 through custom5) for data row-level security;
  • The problem typically manifests when user attributes are defined as arrays in the IDP (e.g., ['Admin', 'Reader', 'Writer']);

Example Scenario:

  • A permission entity was configured with value ' Reader' (with a leading space)
  • Users with the Reader attribute could previously access the protected data
  • After the upgrade, these users can no longer access the data 


Read more...

Environment

  • SAP Datasphere

Product

SAP Datasphere all versions

Keywords

datasphere, data access control, dac, identity provider attributes, custom schema, multi-value attributes, leading space, array values, attribute-based access control, abac, identity cloud services, operator and values, permissions table, custom application attributes, filtering , KBA , DS-SEC-DAC , Security – Data Access Control , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.