Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
getClientForTrustedUser authentication error
mike_s
TeamSite 6.5
CSSDK 2.0
Solaris 8 (5.8)
(originally posted in TeamSite forum before I realised this forum was probably the most appropriate)
I'm trying to create a client object using the getClientForTrustedUser method of the CSLocalFactory class.
No matter what I try a CSAuthenticationException exception is thrown.
I know the user I'm passing exists and can log in to TeamSite. The appContext string is retrieved from the application context of the current client object.
The code I'm using is as follows:
CSClient trustedClient = csFactory.getClientForTrustedUser(username, null, Locale.getDefault(), appContext, null);
the csFactory object was created using a properties file containing the following properties:
com.interwoven.cssdk.factory.CSFactory=com.interwo ven.cssdk.factory.CSLocalFactory
data.cache.timeoutms=100000000
Does anyone know why I'm unable to create the trusted client?
Many thanks in advance
Mike
Find more posts tagged with
Comments
Nicholas
bk99nd having the same issue, you can look on this
thread
hth
mike_s
Thanks for the post.
However, I had already tried adding the cssdk.ssl.key.location property (via code, rather than putting it in the properties file) to a value of '/servletd/conf/ssl_cert' according to the thread you mentioned without success.
Is this property used to generate a file or to read a file? The file does not exist, at least iw-home/servletd/conf/ssl_cert' does not exists (might it exist elsewhere?).
Mike
Bill Klish
My post is dealing with TeamSite 6.7 not 6.5.
Hmm, I thought that this method only exists in TeamSite 6.5 sp1 and newer. Are you compiling this code against the cssdkapi.jar and cssdkjni.jar files?
I don't believe this method exists for that version.
Can you attach or paste in your code? How is the code being called/accessed?
mike_s
The code is as follows:
CSFactory csFactory = CSFactory.getFactory(props);
try {
CSClient trustedClient = csFactory.getClientForTrustedUser(username, null, Locale.getDefault(), appContext, null);
} catch (CSAuthenticationException cae) {
logger.error("Authentication exception caught when attempting to get trusted user " + cae.getMessage());
cae.printStackTrace();
} catch (CSException ce) {
logger.error("Generic exception caught getting client for trusted user " + ce.getMessage());
ce.printStackTrace();
}
I'm compiling against iw-home/cssdk/cssdkiface.jar.
I'm assuming it's the version of ContentServices (now upgraded to 2.5 to no effect with respect to this particular problem) that determines whether the method exists or not, not the version of TeamSite. Am I wrong here?
Mike
mike_s
I get the following when i print the string returned from csFactory.getClass().getName():
Got factory of class com.interwoven.cssdk.factory.CSLocalFactory
so I know I'm getting the right type of factory object.
If I print out all the properties in the properties file returned by csFactory.getConfigProperties I can see the following:
key is allowLocalMode, value is true
key is Logging.methodNameLen, value is 40
key is maxMemoryLimit, value is 1000000
key is Logging.elapsedTimeOnly, value is false
key is Logging.doLog, value is true
key is Logging.recursive, value is true
key is cs.soap.license, value is 00a78bf90dd001e0454bdfb367aff2
key is Logging.methodLoggerFile, value is /var/adm/cssdk.log
key is defaultTSServer, value is sun-iw-dor-3
key is Logging.showDateTime, value is showTime
Can anyone from Interwoven help here?
Basically what I'm trying to achieve is allow certain editors to unlock files and it seemed sensible to me to use the getTrustedClient method to get a client object for a user which can do this. Is this not allowed by the application?
Bill Klish
We use this method in pretty complex external task scripts that are run as full java applications so it is defninetly possible.
Do you get any compile errors?
also, can you include the stack trace?
And you didn't answer how you are invoking/running this.
mike_s
Hi Bill,
I get no compile errors.
I'm invoking this from a servlet running inside the content center webapp.
The stack trace is as follows:
com.interwoven.cssdk.access.CSAuthenticationException: (Authentication error)
at com.interwoven.cssdk.access.jni.CSUserJNIServer.beginSessionUsingFile(Native Method)
at com.interwoven.cssdk.access.jni.AccessServiceAdapterImpl.beginSessionUsingFile(AccessServiceAdapterImpl.java:82)
at com.interwoven.cssdk.factory.CSLocalFactory.getClientForTrustedUser(CSLocalFactory.java:132)
at com.myApp.custom.UnlockFileServlet.processRequest(Unknown Source)
at com.myApp.custom.UnlockFileServlet.doPost(Unknown Source)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:709)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:802)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157)
at com.interwoven.ui.base.impl.auth.AuthenticationFilter.doFilter(AuthenticationFilter.java:206)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157)
at com.interwoven.ui.base.util.SetRequestEncodingFilter.doFilter(SetRequestEncodingFilter.java:105)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157)
at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198)
at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:117)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929)
at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160)
at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799)
at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705)
at org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577)
at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683)
at java.lang.Thread.run(Thread.java:534)
Bill Klish
After thinking about this some more, why are you using that method anyway? If you are providing a custom link that is clicked via a menu option, the CSClient object is always passed along as a request attribute. You should be able to just access the client using the following code:
CSClient client = (CSClient)request.getAttribute("iw.csclient");
That should be all you need.
If you want to still figure out why that error is happening attach the servlet to this post and I will add it into my content center webapp to see if it still works.
Thanks,
-Bill
mike_s
I want to provide certain users with the abilibity to unlock files when they are not the creator of the lock or the workarea owner.
My intention is to create a configuration file containing users who may be granted special unlock capabilities which my serlvet will lookup to check if the user is one of these users and if so use a client object returned by the getClientForTrustedUser() method to perform the unlock.
I haven't attached the servlet because their are a number of dependant bespoke classes which I would need to provide too.
Bill Klish
Ok. I think I follow you. If the current user, which is also available in the request object is in your file, then give them the unlock capability using the CSClient object that is in the request. I am still not seeing the need for the non-authenticated method.
In any event, I will put in the snippets of code you sent me and see if it works on my system. I will let you know.
chuckles
I am having the same problem. I am trying to write a command-line script with no luck. Did any of you guys have any luck with this?
Bill Klish
Yep. It requires a bit of messing around but is doable. Where are you stuck?
chuckles
I worked with IW support on this and eventually got it. For me, it was that I needed read permission on the IW_HOME/private/etc/passphrase file. For everyone else's reference, you will also need these environment variables set (at least in unix you do):
CLASSPATH=IW_HOME/cssdk/cssdkjni.jar:IW_HOME/cssdk/cssdkiface.jar:.
LD_LIBRARY_PATH=IW_HOME/lib:IW_HOME/cssdk
Bill Klish
We have avoided changing the permissions on the pass phrase file as that opens up security concerns on externally accessible systems. This file is what allows a user access into TeamSite.
If your server is on an internal network this is probably an ok solution.
We have gotten it to work without requiring that file to be updated.
chuckles
We are on an internal network, but that still isn't so great from a security perspective. How exactly did you work around it?
Bill Klish
Depends on the version of TeamSite you are using. What version are you on?
chuckles
6.5 SP2, Solaris 9.
Bill Klish
This issue was fixed in SP2.
I am surprised you need to do what you are stating. What user are you trying to run this task as, and how are you attempting to get the CS Client? Is this over SOAP or are you executing the Java script on the server?
Bowker
I don't believe you can get a trusted client via SOAP. That would be a huge security hole.