User has restricted menus and functions to READ only. Example Request or Product
Using API calls with the same user the same data can be modified. Expectation is: since the user has READ only this should not be possible
How to you handle the roles /rights in order to avoid this issue?
Can you reproduce also in your systems?
We use FSM 6.5
Thank you already for any useful feedback!