Interaction method of external system and SAP system
By setting up SAP dedicated account and SAP general interface on the SAP system, combined with the development of the API proxy service system, the problem of high complexity of interaction between the external system and the SAP system is solved, and an efficient and secure interaction method is achieved, reducing development costs and complexity.
Patent Information
- Application Number
- CN202510156225.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2025-06-03
AI Technical Summary
In the prior art, the interaction between the external system and the SAP system is complex, the learning cost is high, and the development efficiency is low, making it difficult to balance cost control and security.
By setting up SAP dedicated account and SAP general interface on the SAP system, the API proxy service system is developed, providing an HTTP interface to the external system and implementing OAuth 2.0 permission authentication, providing dedicated client identification and client key, and implementing the message forwarding function of the SAP general interface in the API proxy service system.
It effectively reduces the development complexity, improves development efficiency, reduces the consumption of SAP system account resources, reduces the permission management configuration work, and ensures the security of SAP data.
Smart Images

Figure CN120086035A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of SAP system interaction, and particularly relates to an interaction method between an external system and an SAP system. Background Art
[0002] The SAP ERP system is a typical representative of the Enterprise Resource Planning (ERP) system, developed and provided by SAP, a globally renowned enterprise management software provider. It is an application software integrating various enterprise management functions, including multiple modules such as financial accounting, management accounting, treasury management, asset management, material management, production planning, sales management, and human resource management. Through high integration among these modules, it realizes the comprehensive optimization and efficient utilization of enterprise resources and is widely used in enterprise management across various industries worldwide.
[0003] The HTTP interface is an application programming interface (API) based on the HTTP (HyperText Transfer Protocol), which defines the specifications and formats for data exchange between the client and the server. The working principle of the HTTP interface is based on the request - response model of the HTTP protocol. The client (such as a browser, a mobile application, another server, etc.) sends an HTTP request to the server, and the request contains the operation to be performed and the resource identifier (such as a URL). After receiving the request, the server executes the corresponding operation according to the content of the request and returns the result to the client in the form of an HTTP response.
[0004] OAuth 2.0 (Open Authorization 2.0) is a widely used open standard authorization protocol, which is powerful and flexible, providing a secure and user - friendly authentication and authorization solution for modern Internet applications. OAuth 2.0 defines four authorization modes to adapt to different application scenarios. ① Authorization Code Grant: The authorization mode with the most complete functions, the widest use, and the most rigorous process. It is applicable to all types of clients, including web applications, mobile applications, and desktop applications. ② Implicit Grant: Applicable to scenarios where the client secret is not required, such as browser - based applications. ③ Resource Owner Password Credentials Grant: Allows the client to directly obtain the access token through the username and password. However, this method has security risks and should be used with caution. ④ Client Credentials Grant: Applicable to direct authentication between the client and the authorization server without user participation.
[0005] SAP PI, whose full name is SAP Process Integration, is a core middleware product launched by SAP and an important part of the SAP NetWeaver platform. SAP PI is mainly used to achieve information exchange and integration between internal enterprise systems and between enterprises and external systems. SAP RFC (Remote Function Call) is a protocol used for remote communication between different systems in the SAP system. RFC allows a program on one SAP system to call and execute a function in another SAP system, achieving seamless integration and data exchange between systems.
[0006] When external systems interact with the SAP ERP system, SAP PI, RFC and other methods are often used, but each method has certain disadvantages. As a core component of the SAP NetWeaver platform, although SAP PI provides powerful functions and flexibility in system integration, this also results in a relatively high complexity. The configuration and maintenance of SAP PI are relatively complex and require professional technical personnel to operate. This increases the operating cost and learning curve of the system and may be difficult for non-professional users to get started quickly. Since SAP PI involves many technologies and concepts, such as message passing interfaces, mappings, forwarding rules, etc., learning and mastering its use requires a high cost and time investment. The configuration of SAP RFC also requires certain professional knowledge and skills, including understanding the communication protocol between systems, setting up routing and authentication, etc., which increases the difficulty and cost of system configuration. And SAP system accounts are paid resources. Configuring dedicated accounts for each external system requires a large amount of permission configuration, which will increase the enterprise's information management cost and financial cost. Using shared accounts will greatly reduce the security and it is difficult to meet the enterprise's data security management requirements.
[0007] For the above problems such as high complexity, high learning cost, low development efficiency, and difficulty in achieving a balance between cost control and security, there is no good solution in the existing technology. Summary of the Invention
[0008] To solve the above problems existing in the prior art, the present invention provides a method for an external system to interact with an SAP system. The technical problems to be solved by the present invention are realized through the following technical solutions:
[0009] The present invention provides a method for an external system to interact with an SAP system, including:
[0010] S1: Set up a dedicated SAP account and an SAP general interface for providing services to external systems on the SAP system;
[0011] S2: Develop an API proxy service system to provide an HTTP interface for the external system and implement OAuth 2.0 permission authentication;
[0012] S3: Provide a dedicated client identifier and client secret for the external system in the API proxy service system;
[0013] S4: Conduct permission authentication for each function in the SAP system in the API proxy service system to use the SAP dedicated account to implement the message forwarding function of the SAP general-purpose interface;
[0014] S5: Perform the interaction between the external system and the SAP system through the SAP general-purpose interface and the API proxy service system.
[0015] In an embodiment of the present invention, the S1 includes:
[0016] S1.1: Add a new user on the SAP system, set the user type, password, and default value information, and assign preset permissions;
[0017] S1.2: Develop a SAP general-purpose interface for providing services for the external system based on the SAP system. The SAP general-purpose interface can receive the function name of the SAP and the parameters required by the function for dynamic invocation and return the execution result.
[0018] In an embodiment of the present invention, the S1.2 includes:
[0019] Add a new class and implement the HANDLE_REQUEST method of the interface IF_HTTP_EXTENSION. In the implementation of the HANDLE_REQUEST method, parse the function name and the parameters required by the function requested by the API proxy service system, dynamically invoke the corresponding SAP function in the SAP system according to the parsed function name and the parameters required by the function, and return the execution result. Among them, the SAP function includes a function or a method of a class;
[0020] Use the transaction code SICF to create and publish a service, set the SAP dedicated account as the specified user accessing the service, and set the implementation class of the interface IF_HTTP_EXTENSION as the service processor.
[0021] In an embodiment of the present invention, the S3 includes:
[0022] In the API proxy service system, dedicated client identifiers and client keys are provided for each external system respectively, and the resource scopes accessible to each external system are set. Among them, the external system can send a request to the API proxy service system carrying the client identifier, client key, and the resource scope to be accessed. After the API proxy service system verifies the correctness of the client identifier and the client key and whether it has the requested access scope, it returns a client access token to the external system.
[0023] In an embodiment of the present invention, S4 includes:
[0024] An HTTP interface is added to the API proxy service system. The HTTP interface can receive the client access token, the function name provided by the SAP system, and the parameters required for the function, verify the validity of the client access token and whether the resource scope accessible by the client access token includes the access scope corresponding to the function name provided by the SAP system. If the verification passes, the function name provided by the SAP system and the parameters required for the function are forwarded to the SAP general-purpose interface provided by the SAP system.
[0025] In an embodiment of the present invention, S5 includes:
[0026] S5.1: The external system requests the API proxy service system to obtain the corresponding client access token carrying the client identifier, client key, and the resource scope to be accessed.
[0027] S5.2: The API proxy service system verifies the correctness of the client identifier and the client key and whether it has the right to access. If the client key is correct and it has the right to access, execute S5.3. If the client key is incorrect or it has no right to access, an error message is returned and the execution ends.
[0028] S5.3: The API proxy service system returns the client access token to the external system and sets a predetermined validity period.
[0029] S5.4: The external system accesses the HTTP interface provided by the API proxy service system carrying the client access token. The API proxy service system verifies the validity of the client access token and the accessible resource scope. If it has the right to access, execute step S5.5. If it has no right to access, an error message is returned and the execution ends.
[0030] S5.5: The API proxy service system sends the function name and the parameters required by the function in the external system request to the SAP general interface. The SAP general interface dynamically invokes the function provided by the SAP system according to the received function name and the parameters required by the function, returns the return value of the execution of the SAP system function to the external system through the API proxy service system, and ends the execution.
[0031] Another aspect of the present invention provides a storage medium in which a computer program is stored. The computer program is used to execute the steps of the interaction method between the external system and the SAP system according to any one of the above embodiments.
[0032] Yet another aspect of the present invention provides an electronic device, including a memory and a processor. A computer program is stored in the memory. When the processor calls the computer program in the memory, the steps of the interaction method between the external system and the SAP system according to any one of the above embodiments are implemented.
[0033] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0034] The present invention provides an interaction method between an external system and an SAP system, which can dynamically call SAP methods through a SAP general interface, effectively reducing the development complexity and improving the development efficiency. When adding new functions, only the implementation logic of this function needs to be concerned without any other configurations; the present invention develops a third-party API proxy service system to proxy the SAP interface service and divides their respective responsibilities. The third-party API proxy service system completes the authentication operation, and the SAP system completes the actual function. By accessing the SAP interface through an independent API proxy service system, only one SAP dedicated account is required, and there is no need to create accounts for each external system separately, saving the account resources of the SAP system and reducing the permission management configuration work of SAP account managers; the present invention uses an independent API proxy service system to control the permissions of each external system, effectively ensuring the security of SAP data and reducing the development difficulty of external system calls.
[0035] The following will further elaborate on the present invention in detail with reference to the drawings and embodiments. Description of the Drawings
[0036] Figure 1 is a flowchart of an interaction method between an external system and an SAP system provided by an embodiment of the present invention;
[0037] Figure 2 is a schematic diagram of the login data interface for creating a new user using the transaction code SU01 provided by an embodiment of the present invention;
[0038] Figure 3It is a schematic diagram of the permission setting interface for creating a new user using the transaction code SU01 provided by an embodiment of the present invention;
[0039] Figure 4 It is a schematic diagram of the property setting interface for a class ZCL_HTTP_METHOD provided by an embodiment of the present invention;
[0040] Figure 5 It is a schematic diagram of the interface for the new method UNLOCK_ACCOUNT of a class ZCL_HTTP_METHOD provided by an embodiment of the present invention;
[0041] Figure 6 It is a schematic diagram of the method interface for a class ZCL_HTTP_RESULT provided by an embodiment of the present invention;
[0042] Figure 7 It is a schematic diagram of the interaction among an external system, an SAP system, and an API proxy service system provided by an embodiment of the present invention;
[0043] Figure 8 It is a flowchart of the interaction process between an external system and an SAP system provided by an embodiment of the present invention. Detailed implementation manners
[0044] In order to further elaborate on the technical means and effects adopted by the present invention to achieve the intended invention purpose, the interaction method between an external system and an SAP system proposed according to the present invention will be described in detail below in conjunction with the accompanying drawings and specific implementation manners.
[0045] The foregoing and other technical contents, features, and effects of the present invention can be clearly presented in the following detailed description in conjunction with the accompanying drawings. Through the description of the specific implementation manners, a more in-depth and specific understanding of the technical means and effects adopted by the present invention to achieve the intended purpose can be obtained. However, the accompanying drawings are only for reference and illustration, and are not used to limit the technical solutions of the present invention.
[0046] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including", or any other variant is intended to cover non-exclusive inclusion, so that an article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the article or device including the said element.
[0047] Please refer toFigure 1 , Figure 1 is a flowchart of an interaction method between an external system and an SAP system provided by an embodiment of the present invention. The interaction method includes:
[0048] S1: Set a dedicated SAP account for the interface service with greater permissions (i.e., the SAP dedicated account) on the SAP system and a general-purpose SAP interface for providing services to the external system.
[0049] Specifically, a new user is added on the SAP system, and information such as the user type, password, and default value is set, and preset permissions are granted. In a specific embodiment, on the SAP system, the transaction code SU01 is used to create a new user, and the user type is set to C communication data, as Figure 2 shown, that is, it is not allowed to log in using the SAP GUI (Graphical User Interface), and a complex password is set or a random password is generated, a reasonable default value is set, and greater permissions are granted, as Figure 3 shown, where the C communication data indicates that it is not allowed to log in using the SAP GUI.
[0050] Next, a general-purpose interface for providing services to the external system (hereinafter referred to as the SAP general-purpose interface) is developed based on the SAP system. The SAP general-purpose interface can receive the function name of the SAP and the parameters required for the function for dynamic invocation and return the execution result.
[0051] Specifically, a new class is added and the HANDLE_REQUEST method of the interface IF_HTTP_EXTENSION is implemented. In the implementation of the HANDLE_REQUEST method, the function name and the parameters required for the function of the API proxy service system request are parsed, and the corresponding SAP function in the SAP system is dynamically invoked according to the parsed function name and the parameters required for the function and the execution result is returned, where the SAP function includes a function or a method of a class; the transaction code SICF is used to create and publish a service, the SAP dedicated account is set as the designated user for accessing the service, and the implementation class of the interface IF_HTTP_EXTENSION is set as the service processor.
[0052] In a specific embodiment, adding a new class and implementing the HANDLE_REQUEST method of the interface IF_HTTP_EXTENSION includes:
[0053] Use transaction code SE24 to create a new class ZCL_HTTP_METHOD. The methods in class ZCL_HTTP_METHOD are service functions for external systems to call. It should be noted that transaction codes (abbreviated as TR) are used in the SAP system to identify and manage specific business operations or functions. Each transaction code has a unique name for performing specific tasks or functions in the SAP system. Transaction codes are usually stored in several specific tables, including the TSTC, TSTCP, and TSTCT tables, which store the basic information, parameter information, and multilingual descriptions of the transaction codes respectively.
[0054] Use transaction code SE24 to create a new class ZCL_HTTP_METHOD, specifically including:
[0055] First, add an attribute R_DATA of type STRING to the newly created class ZCL_HTTP_METHOD to store the return data, as Figure 4 shown. Then, add methods to the newly created class ZCL_HTTP_METHOD. The added methods will be provided as interfaces for external systems to call. Taking the function of unlocking an SAP account as an example, add a new method UNLOCK_ACCOUNT, as Figure 5 shown, where ACCOUNT is the SAP account and USERID is the person currently performing this operation.
[0056] In the UNLOCK_ACCOUNT method, determine whether the user USERID has the permission to use the SAP account ACCOUNT. If the user has the permission, unlock the SAP account and return the unlocking result; otherwise, return an error message indicating unauthorized operation.
[0057] Next, use transaction code SE24 to create a new class ZCL_HTTP_RESULT. Class ZCL_HTTP_RESULT is used to unify the data format returned by the interface. The returned data format includes the attributes code, msg, and data. Among them, the value of code represents whether the interface processing is successful. A value of 200 indicates success, and 500 indicates failure. Other values can be extended to represent different processing states. The value of msg is the return message text, and the value of data is the return data.
[0058] Specifically, add three static methods DATA, ERROR, and OK to class ZCL_HTTP_RESULT, as Figure 6 shown.
[0059] The method DATA is used to encapsulate the data returned by the interface. The parameters of the method DATA include the parameter DATA and the parameter R_JSON. Among them, the parameter DATA is the data that the interface needs to return, and the parameter R_JSON is the encapsulated JSON string. That is, the method DATA is used to encapsulate DATA into a JSON string with the code value of 200, the msg value of ok, and the data value of the parameter DATA.
[0060] The method ERROR is used to generate the return message when the interface processing fails. The parameters of the method ERROR include the parameter MSG and the parameter R_JSON. Among them, the parameter MSG is the error message text, and the default value is error. The parameter R_JSON is the encapsulated JSON string. That is, the method ERROR is used to return a JSON string with the code value of 500, the msg value of the parameter MSG, and the data value empty.
[0061] The method OK is used to generate the return message when the interface processing is successful. The parameters of the method OK include: the parameter MSG and the parameter R_JSON. Among them, the parameter MSG of the method OK is the success message text, and the default value is ok. The parameter R_JSON of the method OK is the encapsulated JSON string.
[0062] That is, the method OK is used to return a JSON string with the code value of 200, the msg value of the parameter MSG, and the data value empty. This method OK is called when the interface only needs to return the processing status and message without any return data.
[0063] Furthermore, use the transaction code SE24 to create a new class ZCL_HTTP_API and implement the HANDLE_REQUEST method of the interface IF_HTTP_EXTENSION. In the HANDLE_REQUEST method, parse the method name (i.e., the method name in ZCL_HTTP_METHOD) and the transmitted parameters from the REQUEST attribute of the method parameter SERVER. Dynamically call the method in ZCL_HTTP_METHOD according to the method name and parameters, and write the return value of the method into the RESPONSE attribute of the parameter SERVER to respond to the API proxy service system.
[0064] It should be noted that the interface IF_HTTP_EXTENSION is an HTTP request handler interface provided by the SAP standard. The processor class selected during the subsequent steps of creating and publishing the service in SICF must implement the IF_HTTP_EXTENSION interface. This interface is used to define the behavior of a certain type of object without involving the specific implementation. The interface IF_HTTP_EXTENSION defines a method HANDLE_REQUEST but does not have the specific implementation of the method. The class ZCL_HTTP_API implementing the interface IF_HTTP_EXTENSION needs to specifically implement the method HANDLE_REQUEST.
[0065] In addition, use the transaction code SICF to create and publish the service, set the SAP dedicated account as the specified user to access the service, and set the class ZCL_HTTP_API as the service processor. The purpose of this step is to publish the HANDLE_REQUEST method in the class ZCL_HTTP_API as a service for external (API proxy service system) calls. That is, after completing this step, the SAP system will provide an accessible URL to the API proxy service system. When accessing this URL, the set SAP dedicated account and password need to be entered, and the access request will be processed and responded by the HANDLE_REQUEST method of the class ZCL_HTTP_API.
[0066] S2: Develop a third-party API proxy service system based on the Java language to provide an HTTP interface for external systems and implement OAuth 2.0 permission authentication.
[0067] Specifically, use SpringBoot to quickly build a Web service as the API proxy service system to implement OAuth 2.0 client mode authentication.
[0068] S3: Provide dedicated client identifiers and client secrets for external systems in the API proxy service system.
[0069] In this step, provide respective dedicated client identifiers and client secrets for each external system in the API proxy service system, and set the accessible resource scope for each external system. Among them, the external system can send a request to the API proxy service system carrying the client identifier, client secret, and the resource scope to be accessed. After the API proxy service system verifies the correctness of the client identifier and client secret and whether it has the requested access scope, it returns a client access token to the external system.
[0070] In a specific embodiment, in the API proxy service system, dedicated Client IDs (client identifiers) and Client Secrets (client keys) are provided for each external system respectively. When each external system requests API services from the API proxy service system, it must carry the Client Token (client access token) obtained through the Client ID and Client Secret. The API proxy service system will verify the validity of the Client Token and the scope of resources it can access (Scope), and release it after successful verification.
[0071] Create a new database table client_model on the API proxy service system. The database table client_model contains fields client_id (primary key) and client_secret, which are used to maintain the key information of each external system. Create a new database table client_scope on the API proxy service system. The database table client_scope contains fields client_id (primary key) and contract_scope (primary key), which are used to maintain the scope of resources that each external system can access.
[0072] When the external system requests the client access token (ClientToken) carrying the Client ID, Client Secret, and Scope, the API proxy service system verifies whether the correspondence between the Client ID and Client Secret is correct according to the data in the database table client_mode, and verifies whether the external system has the right to request the token for this Scope according to the data in the database table client_scope. After both verifications pass, a Client Token with a validity period of 2 hours is returned.
[0073] S4: Use a dedicated SAP account in the API proxy service system to implement the message forwarding function of the SAP general-purpose interface. Perform permission authentication for each function in the SAP system respectively. After successful authentication, call the SAP general-purpose interface to obtain the response data of SAP and return it to the calling system.
[0074] In this step, add an HTTP interface in the API proxy service system. The HTTP interface can receive the client access token, the function name provided by the SAP system, and the parameters required by the function, and verify the validity of the client access token and whether the scope of resources accessible by the client access token includes the access scope corresponding to the function name provided by the SAP system. If the verification passes, forward the function name provided by the SAP system and the parameters required by the function to the SAP general-purpose interface provided by the SAP system.
[0075] In a specific embodiment, a new database table erp_method_scope is created on the API proxy service system. The database table erp_method_scope contains fields erp_method (primary key) and scope, which are used to maintain the Scope corresponding to each SAP method (the methods in class ZCL_HTTP_METHOD in the previous SAP system). That is, the client must have the Scope corresponding to a certain method to access this method. For methods not configured in the table, the corresponding Scope defaults to "ERP_" + the method name.
[0076] A new Controller class is added on the API proxy service system and a callErpMethod method is added to provide an Http interface service for external systems. The callErpMethod method is specifically used to receive the parameter of the ZCL_HTTP_METHOD method name of the SAP system to be accessed and other parameters required by the method. In the callErpMethod method, the validity of the ClientToken and whether it contains the Scope corresponding to the ZCL_HTTP_METHOD method are verified. After passing the verification, the ZCL_HTTP_METHOD method name and other parameters are sent to the SAP general interface and its response is returned.
[0077] Subsequently, the SAP system only needs to add a ZCL_HTTP_METHOD method to automatically and securely publish services to each system for calling through the SAP general interface and the API proxy service system.
[0078] S5: The interaction between the external system and the SAP system is carried out through the SAP general interface and the API proxy service system.
[0079] Please refer to Figure 7 and Figure 8 , and step S5 of this embodiment specifically includes:
[0080] S5.1: The external system requests the API proxy service system with the client identifier, client secret, and the resource scope to be accessed to obtain the corresponding client access token.
[0081] S5.2: The API proxy service system verifies the correctness of the Client ID and Client Secret and whether there is permission to access. If the Client Secret is correct and there is permission, step S5.3 is executed. If the Client Secret is incorrect or there is no permission, an error message is returned and the execution ends.
[0082] S5.3: The API proxy service system returns the Client Token to the external system, with a validity period of 2 hours.
[0083] S5.4: The external system accesses the HTTP interface provided by the API proxy service system with the Client Token. The API proxy service system verifies the validity of the Client Token and the accessible resource scope. If there is permission to access, step S5.5 is executed; if there is no permission to access, an error message is returned and the execution ends.
[0084] S5.5: The API proxy service system sends the method and parameters requested by the external system to the general-purpose interface of the SAP system. The general-purpose interface of the SAP system dynamically invokes the method according to the received function name and the parameters required by the function, returns the return value of the method executed by the SAP system to the external system through the API proxy service system, and the execution ends.
[0085] The present invention provides an interaction method between an external system and an SAP system, which can dynamically call SAP methods through the general-purpose interface of SAP, effectively reducing the development complexity and improving the development efficiency. When adding new functions, only the implementation logic of this function needs to be concerned without any other configuration; the present invention develops a third-party API proxy service system to proxy the SAP interface service and divides their respective responsibilities. The third-party API proxy service system completes the authentication operation, and the SAP system completes the actual function. By accessing the SAP interface through an independent API proxy service system, only one SAP dedicated account is required, and there is no need to create separate accounts for each external system, saving the account resources of the SAP system and reducing the permission management configuration work of SAP account managers; the present invention uses an independent API proxy service system to control the permissions of each external system, effectively ensuring the security of SAP data and reducing the development difficulty of external system calls.
[0086] The above is only one implementation solution of the present invention. The protection scope of the present invention is not limited to the above. Any technical solution that uses a third-party API proxy service system to proxy and forward the SAP interface service belongs to the protection scope of the present invention. Any modification made without departing from the principle of the present invention shall be regarded as within the protection scope of the present invention.
[0087] Another embodiment of the present invention provides a storage medium in which a computer program is stored, and the computer program is used to execute the steps of the interaction method between the external system and the SAP system in the above embodiment. Another aspect of the present invention provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps of the interaction method between the external system and the SAP system as described in the above embodiment are implemented. Specifically, the integrated modules implemented in the form of software function modules can be stored in a computer-readable storage medium. The above software function modules are stored in a storage medium and include several instructions for causing an electronic device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute some steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.
[0088] The above content is a further detailed description of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.
Claims
1. A method for interaction between an external system and a SAP system, characterized in that: include: S1: Set up a SAP dedicated account and a SAP general interface for providing services to external systems on the SAP system; S2: Develop an API proxy service system to provide an HTTP interface for the external system and implement OAuth 2.0 authorization authentication; S3: providing a dedicated client identifier and a client key for the external system in the API proxy service system; S4: performing authority authentication for each function in the SAP system in the API proxy service system, so as to implement the message forwarding function of the SAP universal interface using the SAP dedicated account; S5: The external system interacts with the SAP system through the SAP universal interface and the API proxy service system.
2. The method for interaction between an external system and a SAP system according to claim 1, characterized in that: The S1 includes: S1.1: Add a new user on the SAP system, set the user type, password and default value information, and grant preset permissions; S1.2: A SAP universal interface is developed based on the SAP system to provide services for the external system. The SAP universal interface can receive the SAP function name and function required parameters for dynamic calling and return the execution result.
3. The method for interaction between an external system and a SAP system according to claim 2, characterized in that: The S1.2 includes: Add a new class and implement the HANDLE_REQUEST method of the interface IF_HTTP_EXTENSION, parse the function name and function required parameters requested by the API proxy service system in the implementation of the HANDLE_REQUEST method, dynamically call the corresponding SAP function in the SAP system according to the parsed function name and function required parameters and return the execution result, wherein the SAP function includes a function or a class method; Use transaction code SICF to create and publish a service, set the SAP dedicated account as a designated user to access the service, and set the implementation class of the interface IF_HTTP_EXTENSION as a service processor.
4. The method for interaction between an external system and a SAP system according to claim 1, characterized in that: The S3 includes: In the API proxy service system, each external system is provided with its own dedicated client identifier and client key, and an accessible resource range is set for each external system. The external system can send a request to the API proxy service system with the client identifier, client key and the resource range to be accessed. The API proxy service system verifies the correctness of the client identifier and the client key and whether they have the requested access range, and then returns a client access token to the external system.
5. The method for interaction between an external system and a SAP system according to claim 4, characterized in that: The S4 includes: A new HTTP interface is added in the API proxy service system. The HTTP interface can receive the client access token, the function name and function required parameters provided by the SAP system, verify the validity of the client access token and whether the resource range accessible by the client access token includes the access scope corresponding to the function name provided by the SAP system. If the verification is successful, the function name and function required parameters provided by the SAP system are forwarded to the SAP general interface provided by the SAP system.
6. The method for interaction between an external system and a SAP system according to claim 5, characterized in that: The S5 includes: S5.1: The external system carries the client identifier, client key, and resource scope to be accessed to request the API proxy service system to obtain the corresponding client access token; S5.2: The API proxy service system verifies the correctness of the client identifier and the client key and whether the client has access rights. If the client key is correct and the client has access rights, S5.3 is executed. If the client key is incorrect or the client has no access rights, an error message is returned and the execution ends. S5.3: The API proxy service system returns the client access token to the external system and sets a predetermined validity period; S5.4: The external system carries the client access token to access the HTTP interface provided by the API proxy service system. The API proxy service system verifies the validity of the client access token and the scope of accessible resources. If the client has access rights, step S5.5 is executed. If the client has no access rights, an error message is returned and the execution ends. S5.5: The API proxy service system sends the function name and function required parameters requested by the external system to the SAP universal interface. The SAP universal interface dynamically calls the function provided by the SAP system according to the received function name and function required parameters, returns the return value of the SAP system function execution to the external system through the API proxy service system, and ends the execution.
7. A storage medium storing a computer program, characterized in that: The computer program is used to execute the steps of the method for interaction between an external system and a SAP system as claimed in any one of claims 1 to 6.
8. An electronic device comprising a memory and a processor, characterized in that: The memory stores a computer program, and when the processor calls the computer program in the memory, the steps of the method for interaction between an external system and a SAP system according to any one of claims 1 to 6 are implemented.