Workflow log Security

Sue Doughty Sue.Doughty at odfl.com
Wed Aug 20 09:29:03 EDT 2014


Hi George,

Thank you so much for your response!  I will look into this…..


Sue Doughty
SAP Workflow Analyst
Office: (336) 822-5189

From: sap-wug-bounces at mit.edu [mailto:sap-wug-bounces at mit.edu] On Behalf Of george_caramaliu at yahoo.com
Sent: Wednesday, August 20, 2014 9:16 AM
To: SAP Workflow Users' Group
Subject: Re: Workflow log Security

Hi Sue,

There is a work item preview user exit that you might use to check if the user is authorized to see the description and then display either the test result or another message.
I've never used it, but I found this link:
User Exit for Work Item Preview - SAP Business Workflow - SAP Library<http://help.sap.com/saphelp_nw73EhP1/helpdata/en/4f/34ab542acb2786e10000000a42189d/content.htm>





[http://help.sap.com/static/saphelp_nw73ehp1/en/DITAgraphics/navstart.gif]<http://help.sap.com/saphelp_nw73EhP1/helpdata/en/4f/34ab542acb2786e10000000a42189d/content.htm>











User Exit for Work Item Preview - SAP Business Workflow...<http://help.sap.com/saphelp_nw73EhP1/helpdata/en/4f/34ab542acb2786e10000000a42189d/content.htm>
This user exit gives SAP developers the opportunity to adapt the work item preview in the Business Workplace to suit customer-specific requirement...


View on help.sap.com<http://help.sap.com/saphelp_nw73EhP1/helpdata/en/4f/34ab542acb2786e10000000a42189d/content.htm>

Preview by Yahoo






George Caramaliu
Workflow/ABAP Freelancer
________________________________
From: Sue Doughty <Sue.Doughty at odfl.com<mailto:Sue.Doughty at odfl.com>>
To: 'SAP Workflow Users' Group' <sap-wug at mit.edu<mailto:sap-wug at mit.edu>>
Sent: Monday, August 18, 2014 9:39 PM
Subject: Workflow log Security

Hello,

We are on EHP6 (730), pack 12.

We have a workflow that sends drug test results to the employee’s manager after the results have been entered into SAP…an event is triggered that starts the workflow.  The drug test results is privileged information (medical) and we have to protect it.

In the Workflow log, the task that sends the email has the results in the Task Description…..this is what the email says… (BTW, this is a bogus person in DEV).  Right now anyone can see a workflow log via GOS.

[cid:image001.png at 01CFBC59.2E2D5DB0]


I went in and changed the Graphical Presentation to Only in Technical Workflow log for the task that sends the message….I can see it because I have my settings set to Technical User, but the users (who default to User View) cannot see this task in the log.

[cid:image002.png at 01CFBC59.2E2D5DB0]

The user sees this now…..which does not show the task for the email notification…the log stops with the task before that one.
[cid:image003.png at 01CFBC59.2E2D5DB0]

My problem is that if a user figures out how to change their settings to Technical View, then they can see the test results.

Is there any way to make this task not show in the workflow at all……like the box you can click for container operations….”Step not in Workflow log”?.  If not this…..is there a way to lock down viewing of a workflow log with SAP Security or something to keep the user community from switching to the Technical View of the workflow log?

[cid:image004.png at 01CFBC59.2E2D5DB0]

I’ve looked at the SAP Workflow Book and also googled it and the only thing I could find was Graphical Presentation setting.

Thanks for your help!!










Sue Doughty
SAP Workflow Analyst

[http://www.odfl.com/signature/signature_od_37x37.png]<http://www.odfl.com/>

Office: (336) 822-5189
Fax: (336) 822-5149
Email: Sue.Doughty at odfl.com<mailto:Sue.Doughty at odfl.com>
Helping the World Keep Promises.®

Old Dominion Freight Line, Inc.
500 Old Dominion Way
Thomasville, NC 27360
www.odfl.com<http://www.odfl.com/>
[http://www.odfl.com/signature/signature_facebook_25x25.png]<http://www.facebook.com/OldDominionFreightLine>

[http://www.odfl.com/signature/signature_twitter_25x25.png]<http://twitter.com/ODFL_Inc>

[http://www.odfl.com/signature/signature_youtube_25x25.png]<http://www.youtube.com/ODFLInc>

[http://www.odfl.com/signature/signature_linkedin_25x28.png]<http://www.linkedin.com/company/old-dominion-freight-line>

CONFIDENTIALITY NOTICE: The information contained in this message may be confidential, privileged, proprietary, or otherwise legally exempt from disclosure. If the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this message to the intended recipient, you are hereby notified that you are not authorized to read, print, retain, copy or disseminate this message, any part of it, or any attachments. If you have received this message in error, please delete this message and any attachments from your system without reading the content and notify the sender immediately of the inadvertent transmission. Thank you for your cooperation.


_______________________________________________
SAP-WUG mailing list
SAP-WUG at mit.edu<mailto:SAP-WUG at mit.edu>
http://mailman.mit.edu/mailman/listinfo/sap-wug

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.mit.edu/pipermail/sap-wug/attachments/20140820/fd9b1b41/attachment-0001.htm
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.png
Type: image/png
Size: 57697 bytes
Desc: image001.png
Url : http://mailman.mit.edu/pipermail/sap-wug/attachments/20140820/fd9b1b41/attachment-0004.png
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.png
Type: image/png
Size: 34393 bytes
Desc: image002.png
Url : http://mailman.mit.edu/pipermail/sap-wug/attachments/20140820/fd9b1b41/attachment-0005.png
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image003.png
Type: image/png
Size: 28858 bytes
Desc: image003.png
Url : http://mailman.mit.edu/pipermail/sap-wug/attachments/20140820/fd9b1b41/attachment-0006.png
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image004.png
Type: image/png
Size: 22254 bytes
Desc: image004.png
Url : http://mailman.mit.edu/pipermail/sap-wug/attachments/20140820/fd9b1b41/attachment-0007.png


More information about the SAP-WUG mailing list