SAP AS Java Administration

Java Authorization Concept

8 flashcards · answers and spaced-repetition review in the KnowCard app

In the User Management Engine (UME) authorization concept, why can an administrator never assign a permission directly to a user?
What information does a JEE security role actually contain, and why is calling it just SAP's name for an User Management Engine (UME) role wrong?
An application must protect three things: whether a user may open it at all, a specific Delete activity inside it, and an individual document. Which authorization mechanism guards each?
An administrator holds the action that lets them create and maintain roles. Can they use it to grant themselves a powerful role?
Why does ACL maintenance look and behave differently from one AS Java application to the next?
Can an administrator create a new User Management Engine (UME) action to fine-tune what a role grants?
A user is assigned a security role named Approver in one module of a JEE application, then accesses another module protected by a same-named role. What happens, and how does the User Management Engine (UME) make this manageable?
How does the authorization check for a Java Enterprise Edition (JEE) security role differ from one for an User Management Engine (UME) permission at runtime?

Start learning today

Free to start — download the app or use it in your browser.

Get it on App StoreGet it on Google Play