Skip to content

Conversation

@BraunMatthias
Copy link
Contributor

No description provided.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No "(Inbound)" here?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I just wanted to add (Inbound) in this dedicated diagram to show once. I'd rather hesitate to use it in all titles (text or diagram) because it's common sense that "Inbound Authentication" = "Authentication".

[Learn more about advanced authentication options in Node.js](../../node.js/authentication#strategies){.learn-more}
<div class="impl java">

[Learn more about advanced authentication options](../../java/security#spring-boot){.learn-more}
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All learn-more links are complete sentences that should have an ending, usually a dot.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

done


The building blocks are:

- [Authentication](./authentication )
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- [Authentication](./authentication )
- [(Inbound) Authentication](./authentication )

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

see before

Co-authored-by: René Jeglinsky <rene.jeglinsky@sap.com>
@renejeglinsky
Copy link
Contributor

Those two points are missing if I'm not mistaken:

  • Security Documentation Structure Updates: Add a prominent caution or danger box in the documentation explicitly warning developers not to perform security-related coding such as token creation or direct platform service handling, emphasizing strict decoupling from business logic. (Matthias)

  • Authentication Strategy Guidance: Update the XSUAA section to include a clear info box stating to only use XSUA if IAS cannot be used, and otherwise always use IAS. (Matthias)

@BraunMatthias
Copy link
Contributor Author

Those two points are missing if I'm not mistaken:

  • Security Documentation Structure Updates: Add a prominent caution or danger box in the documentation explicitly warning developers not to perform security-related coding such as token creation or direct platform service handling, emphasizing strict decoupling from business logic. (Matthias)
  • Authentication Strategy Guidance: Update the XSUAA section to include a clear info box stating to only use XSUA if IAS cannot be used, and otherwise always use IAS. (Matthias)

done

@renejeglinsky renejeglinsky merged commit 20c8fde into main Jan 23, 2026
7 of 8 checks passed
@renejeglinsky renejeglinsky deleted the security-guide-menu-structure branch January 23, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants