Field Control Annotations for Authorization Objects
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing application development processes are cumbersome and error-prone due to manual configuration of field control access rights in user interfaces (UIs), which complicates data retrieval and authorization management within databases.
Innovation Solution
The implementation of Data Control Language (DCL) annotations that associate authorization objects with Core Data Services (CDS) objects, enabling automatic generation of UIs based on an underlying object model and encapsulating field control data, thereby streamlining access rights management and reducing unauthorized data access requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual development is used to include field control access rights in the UI, then authorization control can be implemented, but the process becomes tiresome and error-prone
Solution Approach 1:
The patent applies preliminary action by pre-defining authorization objects and field control annotations in the CDS layer before UI generation. The field control annotations are prepared in advance with proper authorization assignments, so that when the UI is automatically generated, the authorization control is already configured correctly without requiring manual intervention during UI development.
Solution Approach 2:
The system applies self-service by enabling automatic generation of UI field control annotations from CDS object metadata and authorization objects. The development framework automatically retrieves authorization information and generates the appropriate field control configurations without requiring manual programming, making the system configure itself.
2Productivity
If automatic UI generation is implemented, then development time is reduced, but field control access rights may not be properly configured
Solution Approach 1:
The patent implements feedback by establishing a metadata-driven architecture where the UI generation process continuously references and validates against the CDS object metadata and authorization objects. The system feedback loop ensures that field control annotations are generated based on the actual authorization configuration, allowing verification and correction of authorization accuracy during the automatic generation process.
Solution Approach 2:
The patent applies segmentation by separating the authorization definition (CDS objects and authorization objects) from the UI generation process. This segmentation allows the authorization layer to be independently configured and validated, then automatically translated into field control annotations during UI generation, ensuring both automation and accuracy.
3Reliability
If detailed field control annotations are manually created for each UI field, then precise authorization control is achieved, but data retrieval complexity increases
Solution Approach 1:
The patent applies universality by creating a standardized field control annotation structure that serves multiple functions simultaneously. The same annotation mechanism handles both data retrieval configuration and authorization control enforcement across all UI fields. This universal approach eliminates the need for separate complex configurations for each function, simplifying the overall data retrieval structure while maintaining precise field-level access control.
Data Source
AI summary
An application scaffold is generated based on an object model. The object model includes CDS objects and DCL objects. The CDS objects and the DCL objects are evaluated together with corresponding CDS annotations and DCL annotations. Based on the evaluation, a field control hub is generated. The field control hub evaluates the DCL annotations and determines, based on one or more authorization objects from the DCL annotations, field control data for a field from a number of fields of a UI. When a user requests the UI, the field of the UI is displayed in accordance with the determined field control data for a role of the user.


