The current handling on authorization check result is: if checks is successful, navigate to edit page, or else display error message.
And any end user who is able to use Chrome development tool can manually change the ActionSuccessful to ‘X’ even if he didn’t have enough authorization in the backend.
So is this authorization check really necessary since it could somehow be bypassed. What if an unauthorized user has circumvented this check and continuously executed the code of opportunity save? Is there any authorization check embedded in CRM_ORDER_MAINTAIN?

