Understanding Security Synchronization

To function correctly, the permissions of the group space must be the same as the associated content reference object of the transaction page. Your PeopleSoft applications use the WebCenter SpaceWebService to create and maintain group spaces security that is synchronized to PeopleSoft security. You must configure the web service security for the WEBCENTER node before using any of the WebCenter related content services. Currently, SAML token web service security is the only security type that the WebCenter application supports to consume WebCenter web services.

When a WebCenter service creates a groups space for a transaction page or its transaction instances, all user roles with access to the content reference object are added as user group members with the contributor privilege. WebCenter supports transaction data security at the role level only. Any user who has access to a transaction page is granted access to all group spaces that are created for that page or its transaction instances. If permissions change for a transaction page, the same changes must be reflected in the WebCenter permissions. You synchronize security by running the WebCenter Security batch process.

WebCenter Security Batch Process

The WebCenter Security sync batch process maintains security synchronization between PeopleSoft transactions and WebCenter services.

Important:

You should run this process when the permissions of any transaction page that uses one of the WebCenter related content services changes.

The WebCenter Security synchronization process:

  1. Retrieves a list of expected user group members of the group space.

    This list consists of the roles that have access based on the permission lists that appear on the Security tab of the content reference object for the transaction page.

  2. Adds the user roles that do not exist in the list.

  3. Adds a moderator user group member, if you specify a default moderator role on the WebCenter Options page.

  4. Removes user group members that do not appear in the list.

  5. Removes individual user members that do not have one of the listed user roles.

Note these points about the security synchronization process:

  • The batch process should be run only once after a transaction page permissions are changed to update permissions of existing group spaces.

  • The batch process updates only those group spaces that the WebCenter related content services created.

  • The batch process does not change the permissions of group spaces that are linked to a transaction page or its transaction instances by the WebCenter Links service.

    Note:

    Links do not appear to users if permission to access the associated target is not granted.