I have noticed a few things about OTCSTICKET and REST that I find to be strange and was wondering if anyone had insight on these issues.
I can make an auth called to our Content Server environment and pass in a totally fake user name and password. For example: username=testuser;password=testpassword. When I do this, an OTCSTICKET is granted successfully. I can then use this OTCSTICKET to upload or manipulate files within a specific Content Server folder that this fake user obviously does not have permissions to (since the user does not really exist). This is obviously really unsecure. Is that a bug or is this how it is supposed to work?
I have also noticed that if I request an OTCSTICKET from one machine using something like POSTMAN, I am not able to then use that OTCSTICKET to make subsequent calls from another machine. If I do, I get 401 errors. In this scenario, the calling user would be 2 different people on 2 different machines, but both trying to use the same OTCSTICKET. If I request an individual OTCSTICKET in each environment, subsequent calls will work just fine, as long as they originate from the same environment. I cannot figure out why this is exactly as it doesn't make a lot of sense. Does Content Server only accept the request if the account hitting the REST API is the same that requested the ticket?