ロールデータアクセス制限(Role Data Access)|iDempiere 13 画面リファレンス
ロールデータアクセス制限(Role Data Access)
Section titled “ロールデータアクセス制限(Role Data Access)”iDempiere 13 標準ウィンドウ(AD_Window_ID: 268)
メニュー: システム管理 ▸ 全般設定 ▸ セキュリティ管理 ▸ ロールデータアクセス制限
Maintain Data Access Rules
Maintain Data Access Roles of Roles/Responsibilties. Note that access information is cached and requires re-login or reset of cache.
| # | タブ | テーブル | 階層 | 説明 |
|---|---|---|---|---|
| 10 | ロールデータアクセス | AD_Role | 0 | Role with Data Access Restriction |
| 20 | テーブルアクセス | AD_Table_Access | 1 | Maintain Table Access |
| 30 | カラムアクセス | AD_Column_Access | 1 | Maintain Column Access |
| 40 | レコードアクセス | AD_Record_Access | 1 | Maintain Record Access |
ロールデータアクセス タブのフィールド
Section titled “ロールデータアクセス タブのフィールド”Select Role for with Data Access Restrictions. Note that access information is cached and requires re-login or reset of cache.
| フィールド | カラム | 型 | 必須 | 説明 |
|---|---|---|---|---|
| クライアント | AD_Client_ID | Table Direct | ✔ | Tenant for this installation. |
| 組織 | AD_Org_ID | Table Direct | ✔ | Organizational entity within tenant |
| 名称 | Name | String | ✔ | Alphanumeric identifier of the entity |
| 説明 | Description | String | Optional short description of the record | |
| 初期値設定レベル | PreferenceType | List | ✔ | Determines what preferences the user can set |
| 変更ログ | IsChangeLog | Yes-No | ✔ | Maintain a log of changes |
| 会計情報表示許可 | IsShowAcct | Yes-No | ✔ | Users with this role can see accounting information |
| 全組織アクセス許可 | IsAccessAllOrgs | Yes-No | ✔ | Access all Organizations (no org access control) of the tenant |
| レポート閲覧許可 | IsCanReport | Yes-No | ✔ | Users with this role can create reports |
| エクスポート許可 | IsCanExport | Yes-No | ✔ | Users with this role can export data |
| レコードアクセス権限設定許可 | IsPersonalLock | Yes-No | ✔ | Allow users with role to lock access to personal records |
| 制限されているレコードへのアクセス許可 | IsPersonalAccess | Yes-No | ✔ | Allow access to all personal records |
| Role Template | IsMasterRole | Yes-No | ✔ | A role template cannot be assigned to users, it is intended to define access to menu option and documents and inherit to other roles |
テーブルアクセス タブのフィールド
Section titled “テーブルアクセス タブのフィールド”If listed here, the Role can(not) access all data of this table, even if the role has access to the functionality.
If you Include Access to a table and select Read Only, you can only read data (otherwise full access).
If you Exclude Access to a table and select Read Only, you can only read data (otherwise no access).
Please note that table access rules here are in addition to the Data Access Levels defined for a Table and the User Level defined for a Role. These rules are evaluated first and you only need to define the exceptions to these rules here.
Note that access information is cached and requires re-login or reset of cache. Be aware that if you use Include rules, then you need to include also several supporting entities. As an alternative, grant access only to functionality required.
| フィールド | カラム | 型 | 必須 | 説明 |
|---|---|---|---|---|
| クライアント | AD_Client_ID | Table Direct | ✔ | Tenant for this installation. |
| 組織 | AD_Org_ID | Table Direct | ✔ | Organizational entity within tenant |
| ロール | AD_Role_ID | Table Direct | ✔ | Responsibility Role |
| テーブル | AD_Table_ID | Table Direct | ✔ | Database Table information |
| 有効 | IsActive | Yes-No | ✔ | The record is active in the system |
| アクセス不可 | IsExclude | Yes-No | ✔ | 除外する |
| アクセスタイプ | AccessTypeRule | List | ✔ | The type of access for this rule |
| 読取専用 | IsReadOnly | Yes-No | ✔ | Field is read only |
カラムアクセス タブのフィールド
Section titled “カラムアクセス タブのフィールド”If listed here, the Role can(not) access the column of this table, even if the role has access to the functionality.
If you Include Access to a column and select Read Only, you can only read data (otherwise full access).
If you Exclude Access to a column and select Read Only, you can only read data (otherwise no access).
Note that access information is cached and requires re-login or reset of cache.
| フィールド | カラム | 型 | 必須 | 説明 |
|---|---|---|---|---|
| クライアント | AD_Client_ID | Table Direct | ✔ | Tenant for this installation. |
| 組織 | AD_Org_ID | Table Direct | ✔ | Organizational entity within tenant |
| ロール | AD_Role_ID | Table Direct | ✔ | Responsibility Role |
| テーブル | AD_Table_ID | Table Direct | Database Table information | |
| カラム | AD_Column_ID | Table Direct | ✔ | Column in the table |
| 有効 | IsActive | Yes-No | ✔ | The record is active in the system |
| アクセス不可 | IsExclude | Yes-No | ✔ | 除外する |
| 読取専用 | IsReadOnly | Yes-No | ✔ | Field is read only |
レコードアクセス タブのフィールド
Section titled “レコードアクセス タブのフィールド”You create Record Access records by enabling “Personal Lock” for the administrative role and Ctl-Lock (holding the Ctrl key while clicking on the Lock button).
If listed here, the Role can(not) access the data records of this table, even if the role has access to the functionality.
If you Include Access to a record and select Read Only, you can only read data (otherwise full access).
If you Exclude Access to a recorf and select Read Only, you can only read data (otherwise no access).
Note that access information is cached and requires re-login or reset of cache.
| フィールド | カラム | 型 | 必須 | 説明 |
|---|---|---|---|---|
| クライアント | AD_Client_ID | Table Direct | ✔ | Tenant for this installation. |
| 組織 | AD_Org_ID | Table Direct | ✔ | Organizational entity within tenant |
| ロール | AD_Role_ID | Table Direct | ✔ | Responsibility Role |
| テーブル | AD_Table_ID | Table Direct | ✔ | Database Table information |
| レコードID | Record_ID | Record ID | ✔ | Direct internal record ID |
| 有効 | IsActive | Yes-No | ✔ | The record is active in the system |
| アクセス不可 | IsExclude | Yes-No | ✔ | 除外する |
| 読取専用 | IsReadOnly | Yes-No | ✔ | Field is read only |
| 依存エンティティ | IsDependentEntities | Yes-No | ✔ | 依存エンティティを確認する |