xs-security.json Security Descriptor File
The xs-security.json security descriptor file is a configuration file that developers use to define authorization information for business users in their applications, including scopes, attributes, and role templates. It is passed when creating or updating an instance of the SAP Authorization and Trust Management Service (XSUAA), binding the application's security model to the platform. Developers must follow the Application Security Descriptor Configuration Syntax when authoring the file, and should take care to make only compatible changes when updating an existing service instance to avoid breaking deployed applications.
Docs explaining this concept
- Doc Add Authentication and Functional Authorization Checks to Your Application
- Doc Adding Authentication and Authorization
- Doc Application Security Descriptor Configuration Syntax
- Doc Building Roles and Role Collections for Applications
- Doc Compatible Changes in the Security Descriptor File
- Doc Configure Token Policy for SAP Authorization and Trust Management Service
- Doc Protecting Your Application
- Doc Update a Service Instance