<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic process definition security in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/process-definition-security/m-p/46149#M25843</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Does BPMN2 foresee a way to secure the start event in a process ? Like you have assignment groups for a task, is there something similar for the start event ? In our case not every user is allowed to start (or even see) all available workflows, they are divided by business department with each their own responsibilities.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What i am trying to get to with above question is this: if we have one activiti database per organization, and all process definitions are put there, how can we prevent users from starting workflows they have no business starting ? One way would be to dedicate one activiti database to an application, this is doable but has its own set of advantages/disadvantages in terms of management. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;How do other people deploy activiti for multiple applications / departments ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Jorg&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Apr 2011 09:37:00 GMT</pubDate>
    <dc:creator>heymjo</dc:creator>
    <dc:date>2011-04-29T09:37:00Z</dc:date>
    <item>
      <title>process definition security</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/process-definition-security/m-p/46149#M25843</link>
      <description>Hi,Does BPMN2 foresee a way to secure the start event in a process ? Like you have assignment groups for a task, is there something similar for the start event ? In our case not every user is allowed to start (or even see) all available workflows, they are divided by business department with each th</description>
      <pubDate>Fri, 29 Apr 2011 09:37:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/process-definition-security/m-p/46149#M25843</guid>
      <dc:creator>heymjo</dc:creator>
      <dc:date>2011-04-29T09:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: process definition security</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/process-definition-security/m-p/46150#M25844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;In activiti, there is no way of 'limiting' the process that can be started by a specific user, based on roles/groups. The way the alfresco-integration fixes this (for multi-tennant setups) is prefix the workflow-definitions with the tennant domain. The layer on top of activiti (which alfresco actually uses and exposes) filters the ones out, which are in another domain (based on their name).&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Apr 2011 09:41:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/process-definition-security/m-p/46150#M25844</guid>
      <dc:creator>frederikherema1</dc:creator>
      <dc:date>2011-04-29T09:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: process definition security</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/process-definition-security/m-p/46151#M25845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;yes i had thought about something like that as well, maybe even using the category attribute of a process definition instead of prefixing it. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The issue essentially is that you need to give your users(=applications) a database connection to the schema, so even using a filtering layer and telling them to use only that layer for obtaining process definitions / instances only covers partially the security issues (they can always bypass the filtering layer and use activiti engine directly). Since we have Oracle we can use virtual private databases (VPD) but i did not find a good column in the activiti tables to apply the policy to. For our inhouse products that need to be 'multi-tennant' we always foresee an 'application' column in all tables, so when the user logs on to an application the VPD strips out all data not linked to the current app for all tables - this cannot be circumvented by the schema user.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Maybe the best option is to have an activiti database per application, this makes it easier to evolve versions as well but has the management overhead ofcourse. a tradeoff as always …&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Apr 2011 10:17:09 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/process-definition-security/m-p/46151#M25845</guid>
      <dc:creator>heymjo</dc:creator>
      <dc:date>2011-04-29T10:17:09Z</dc:date>
    </item>
  </channel>
</rss>

