All skills
secondsky avatar

/sap-btp-build-work-zone-advanced

@620a19a
by Eddiesecondsky/sap-skills456 stars
120

Develops and administers SAP Build Work Zone, advanced edition digital workplace solutions. Use when creating workspaces, workpages, and collaborative sites, developing UI Integration Cards in SAP Business Application Studio, building content packages and workspace templates, integrating with Microsoft 365/Teams/SharePoint/Google Drive, configuring chatbots and webhooks, implementing SCIM API user provisioning, setting up OData business records, managing themes and branding, configuring role-based access and SSO, troubleshooting deployment issues, or working with the Administration Console. Keywords: SAP Build Work Zone advanced edition, digital workplace, UI Integration Cards, content packages, workspace templates, SAP Business Application Studio, SAP Conversational AI, SCIM API, OData, Microsoft Teams integration, SSO, theming, Administration Console

Use this Skill: https://skilld.dev/gh/secondsky/sap-skills/sap-btp-build-work-zone-advanced

This session only. Nothing lands on disk.

referencessecurity.md

≈918 tokens on demand. Your agent reads this file only when SKILL.md points to it.

SAP Build Work Zone Security Guide

Security configuration for SAP Build Work Zone, advanced edition.

Source: https://github.com/SAP-docs/sap-btp-build-work-zone-advanced

Table of Contents


Authentication Methods

SAML Identity Providers

Configure trusted SAML IdPs for SSO:

  1. Navigate to Administration Console
  2. Go to Authentication > SAML Trusted IdPs
  3. Add IdP metadata

OAuth Clients

Register OAuth clients for API access:

  1. Go to Authentication > OAuth Clients
  2. Create new client
  3. Configure scopes and permissions

Single Sign-On (SSO)

SSO is enabled through:

  • SAML federation
  • SAP Cloud Identity Services
  • Corporate IdP integration

Access Control

Role Collections

Key roles:

  • Workzone_Admin - Full administration
  • Workzone_User - Standard access
  • Workzone_HR_Admin - HR integration

Workspace Permissions

  • Owner
  • Admin
  • Member
  • Viewer

HTTP Security Headers

Configure security headers to protect against common web vulnerabilities.

Recommended Headers

Header Value Protection
X-Frame-Options SAMEORIGIN Clickjacking
Content-Security-Policy default-src 'self' XSS, content injection
X-Content-Type-Options nosniff MIME-type sniffing
X-XSS-Protection 1; mode=block Cross-site scripting
Strict-Transport-Security max-age=31536000 Protocol downgrade

Example Configuration

X-Frame-Options: SAMEORIGIN
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=31536000; includeSubDomains

Configuration Location

Security headers are typically configured at:

  • BTP Application Router (xs-app.json)
  • SAP Cloud Connector
  • Load balancer/reverse proxy level

Note: For API security including OAuth flows and token handling, see references/api-reference.md.


Compliance Features

Compliance Monitor

Flags content matching compliance dictionary terms.

Profanity Monitor

Detects and flags profanity violations.

Content Administration

Review and manage flagged content.


Audit Logging

Security events logged include:

  • Authentication attempts
  • Permission changes
  • Content modifications
  • Administrative actions

For detailed audit logging configuration, see references/auditing.md.


Documentation Links:

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides comprehensive documentation, reference guides, and templates for the development and administration of SAP Build Work Zone, advanced edition. No security issues were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    3/20 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 620a19a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 months ago
Other metadata
metadata
{
  "maintainer": "Eduard Jiglau",
  "maintainer_email": "hello@sap-ai-skills.com",
  "website": "https://sap-ai-skills.com",
  "version": "2.4.1",
  "last_verified": "2025-11-27"
}

README badge

README badge for secondsky/sap-skills/sap-btp-build-work-zone-advanced