All skills
secondsky avatar

/sap-abap-cds

@620a19a
by Eddiesecondsky/sap-skills456 stars
120

Comprehensive SAP ABAP CDS (Core Data Services) reference for data modeling, view development, and semantic enrichment. Use when creating CDS views or view entities, defining data models with annotations, working with associations and cardinality, implementing input parameters, using built-in functions, writing CASE expressions, implementing access control with DCL, handling CURR/QUAN data types, troubleshooting CDS errors, querying CDS views from ABAP, or displaying data with SALV IDA. Covers ABAP 7.4+ through ABAP Cloud.

Use this Skill: https://skilld.dev/gh/secondsky/sap-skills/sap-abap-cds

This session only. Nothing lands on disk.

referencesaccess-control-reference.md

≈2.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

ABAP CDS Access Control Reference

Complete reference for implementing access control in ABAP CDS using DCL (Data Control Language).

Source: https://help.sap.com/doc/abapdocu_latest_index_htm/latest/en-US/abencds_authorizations.htm

Version Note: CDS access control with implicit role evaluation in ABAP SQL requires 7.50+. Basic DCL (DEFINE ROLE with pfcg_auth) is available from 7.40 SP08. Full access rules, inherited access rules, and user conditions require 7.51+. On 7.40, DCL roles are defined but not automatically enforced in ABAP SQL.


Overview

CDS Access Control provides row-level security for CDS views. Access rules are defined in DCL (Data Control Language) source files that map to CDS views and restrict data based on:

  • PFCG authorization objects
  • Literal conditions
  • User identity
  • Combination of conditions

Creating Access Control in ADT

  1. File → New → Other → Core Data Services → Access Control
  2. Enter:
    • Name: Same as CDS view or custom name
    • Description
    • Protected Entity: The CDS view to protect
  3. Select template

Basic DCL Structure

@EndUserText.label: 'Access Control for Z_CDS_VIEW'
@MappingRole: true
define role Z_CDS_VIEW_DCL {
  grant select on Z_CDS_VIEW
    where condition;
}

Key Elements

Element Purpose
@MappingRole: true Required - maps role to all users
define role Creates the access control object
grant select on Specifies the protected CDS view
where Defines the access condition

Authorization Check Annotation

Control whether DCL is required:

@AccessControl.authorizationCheck: #CHECK
define view Z_CDS_VIEW as select from ...
Value Behavior
#NOT_REQUIRED No DCL needed, full access granted
#CHECK Warning if no DCL exists
#MANDATORY Syntax error if no DCL exists
#NOT_ALLOWED Any existing DCL is ignored

Condition Types

1. PFCG Authorization Condition

Map CDS fields to PFCG authorization objects:

@MappingRole: true
define role Z_SALES_DCL {
  grant select on Z_SALES_ORDER
    where (bukrs) = aspect pfcg_auth(F_BKPF_BUK, BUKRS, ACTVT = '03');
}

Syntax:

where (cds_field) = aspect pfcg_auth(AUTH_OBJECT, AUTH_FIELD, ACTVT = 'value')

Components:

  • cds_field: Field from the CDS view
  • AUTH_OBJECT: Authorization object (from SU21)
  • AUTH_FIELD: Authorization field within the object
  • ACTVT: Activity (usually '03' for display)

2. Multiple Authorization Fields

where (vkorg, vtweg, spart) =
  aspect pfcg_auth(V_VBAK_VKO, VKORG, VTWEG, SPART, ACTVT = '03');

Fields are mapped positionally to authorization fields.

3. Multiple Authorization Objects

@MappingRole: true
define role Z_COMPLEX_DCL {
  grant select on Z_CDS_VIEW
    where (bukrs) = aspect pfcg_auth(F_BKPF_BUK, BUKRS, ACTVT = '03')
      and (vkorg, vtweg, spart) =
          aspect pfcg_auth(V_VBAK_VKO, VKORG, VTWEG, SPART, ACTVT = '03');
}

4. Literal Condition

Compare field to fixed value:

@MappingRole: true
define role Z_ACTIVE_ONLY_DCL {
  grant select on Z_CDS_VIEW
    where status = 'ACTIVE';
}

Operators:

  • = Equal
  • <> Not equal
  • <, >, <=, >= Comparison
  • between ... and ... Range
  • like Pattern matching

5. User Aspect

Restrict to current user:

@MappingRole: true
define role Z_USER_DCL {
  grant select on Z_USER_DATA
    where created_by ?= aspect user;
}

Note: ?= allows NULL values to match.

6. Environment Aspect

Access environment values:

where client = aspect environment.client

Operator Variants

Standard Operator (=)

where (bukrs) = aspect pfcg_auth(...)

Only authorized values returned.

Optional Operator (?=)

where (bukrs) ?= aspect pfcg_auth(...)

NULL and initial values also allowed.


Combining Conditions

AND Combination

where (bukrs) = aspect pfcg_auth(F_BKPF_BUK, BUKRS, ACTVT = '03')
  and status = 'ACTIVE'
  and created_by ?= aspect user;

OR Combination

where status = 'PUBLIC'
   or created_by ?= aspect user;

Complex Logic

where (
    (bukrs) = aspect pfcg_auth(F_BKPF_BUK, BUKRS, ACTVT = '03')
    and status = 'ACTIVE'
  )
  or status = 'PUBLIC';

Inheritance and Propagation

No Automatic Inheritance

Access control does NOT automatically apply when:

  • CDS view is used as data source in another view
  • View is accessed via association

Each view needs its own DCL for protection.

Recommended Pattern

Create DCL for all views in a hierarchy:

-- Base view DCL
define role Z_BASE_DCL {
  grant select on Z_BASE_VIEW
    where (bukrs) = aspect pfcg_auth(...);
}

-- Consumer view DCL
define role Z_CONSUMER_DCL {
  grant select on Z_CONSUMER_VIEW
    where (bukrs) = aspect pfcg_auth(...);
}

Common Authorization Objects

Finance

Object Fields Description
F_BKPF_BUK BUKRS, ACTVT Company code
F_BKPF_GSB GSBER, ACTVT Business area
F_BKPF_KOA KOART, ACTVT Account type

Sales

Object Fields Description
V_VBAK_VKO VKORG, VTWEG, SPART, ACTVT Sales org/channel/division
V_VBAK_AAT AUART, ACTVT Order type

Materials

Object Fields Description
M_MATE_WRK WERKS, ACTVT Plant
M_MATE_MAR MTART, ACTVT Material type

Controlling

Object Fields Description
K_CCA KOKRS, KOSTL, ACTVT Cost center
K_ORDER AUFNR, ACTVT Internal order

Find objects: Transaction SU21 (Authorization Objects)


Activity Values (ACTVT)

Value Activity
01 Create
02 Change
03 Display
06 Delete
16 Execute

Most CDS views use ACTVT = '03' (display).


Examples

Company Code Authorization

@MappingRole: true
define role Z_COMPANY_DCL {
  grant select on Z_FINANCIAL_DATA
    where (bukrs) = aspect pfcg_auth(F_BKPF_BUK, BUKRS, ACTVT = '03');
}

Sales Organization + Status Filter

@MappingRole: true
define role Z_SALES_DCL {
  grant select on Z_SALES_ORDER
    where (vkorg, vtweg, spart) =
          aspect pfcg_auth(V_VBAK_VKO, VKORG, VTWEG, SPART, ACTVT = '03')
      and status <> 'DELETED';
}

Own Records Only

@MappingRole: true
define role Z_OWN_DATA_DCL {
  grant select on Z_USER_TASKS
    where assigned_to ?= aspect user;
}

Public + Owned Records

@MappingRole: true
define role Z_MIXED_DCL {
  grant select on Z_DOCUMENTS
    where visibility = 'PUBLIC'
       or created_by ?= aspect user;
}

Multi-level Authorization

@MappingRole: true
define role Z_MULTILEVEL_DCL {
  grant select on Z_MATERIAL_DATA
    where (werks) = aspect pfcg_auth(M_MATE_WRK, WERKS, ACTVT = '03')
      and (mtart) = aspect pfcg_auth(M_MATE_MAR, MTART, ACTVT = '03');
}

Testing Access Control

In ADT

  1. Right-click CDS view → Open With → Data Preview
  2. Data shown reflects current user's authorizations

Via ABAP

" Access control automatically applied
SELECT * FROM z_secured_view
  INTO TABLE @DATA(lt_data).

" Bypass access control (if allowed)
SELECT * FROM z_secured_view
  BYPASSING BUFFER
  INTO TABLE @DATA(lt_all_data).

Note: BYPASSING BUFFER does NOT bypass DCL.

Checking User Authorizations

AUTHORITY-CHECK OBJECT 'F_BKPF_BUK'
  ID 'BUKRS' FIELD '1000'
  ID 'ACTVT' FIELD '03'.

IF sy-subrc = 0.
  " User has authorization
ENDIF.

Best Practices

  1. Always add DCL for sensitive data: Don't rely on application-level checks alone
  2. Use #CHECK or #MANDATORY: Avoid accidental exposure
  3. Match cardinality: Ensure DCL doesn't create unexpected duplicates
  4. Test with multiple users: Verify different authorization profiles
  5. Document authorization requirements: Comment the DCL source
  6. Use ?= for optional fields: Handle NULL values gracefully

Troubleshooting

No Data Returned

  1. Check user's PFCG role assignments
  2. Verify authorization object values in SU21
  3. Test authorization with AUTHORITY-CHECK
  4. Check DCL condition logic

Syntax Errors

  1. Verify CDS view exists
  2. Check field names match exactly
  3. Verify authorization object/field names

Performance Issues

  1. Ensure proper indexes on authorization fields
  2. Consider restructuring complex OR conditions
  3. Test with representative data volumes

Documentation Links

Last Updated: 2025-11-23

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    The skill provides comprehensive reference material, templates, and troubleshooting guides for SAP ABAP CDS development. It consists entirely of documentation and static templates without executable code. All external references point to official SAP resources and well-known community repositories.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer6mo

    5/12 files flagged

Signed by skilld at 620a19a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 months ago
Other metadata
metadata
{
  "maintainer": "Eduard Jiglau",
  "maintainer_email": "hello@sap-ai-skills.com",
  "website": "https://sap-ai-skills.com",
  "version": "2.4.1",
  "last_verified": "2026-04-02",
  "abap_release": "7.4 SP8+ / 7.50+ / ABAP Cloud",
  "sources": [
    "https://help.sap.com/doc/abapdocu_cp_index_htm/CLOUD/en-US/abencds.html",
    "https://github.com/SAP-samples/abap-cheat-sheets"
  ],
  "keywords": [
    "ABAP CDS",
    "Core Data Services",
    "CDS view",
    "CDS view entity",
    "define view",
    "DDL",
    "DCL",
    "annotations",
    "@AbapCatalog",
    "@AccessControl",
    "@EndUserText",
    "@Semantics",
    "@UI",
    "@Consumption",
    "@ObjectModel",
    "associations",
    "cardinality",
    "path expressions",
    "input parameters",
    "WITH PARAMETERS",
    "built-in functions",
    "CASE expression",
    "CAST",
    "session variables",
    "GROUP BY",
    "HAVING",
    "joins",
    "access control",
    "DEFINE ROLE",
    "pfcg_auth",
    "SALV IDA",
    "Eclipse ADT",
    "CDS annotations",
    "Fiori Elements",
    "OData",
    "RAP",
    "currencyCode",
    "unitOfMeasure",
    "SD_CDS_ENTITY105"
  ]
}

README badge

README badge for secondsky/sap-skills/sap-abap-cds