Hi,
how to do ImpersonateUser in Java if Webservices are RCS deployed?
Thanks Günter
i have seen a lot of experts viewed this topic already. Is there nobody at OpenText experts who knows the answer?
Hi Guenter,
I don’t work with RCS, so I am unable to comment on this topic.
Have you tried opening a support ticket through My Support to get a subject matter expert?
Regards,
Kyle
You will also have to describe how you have authentication configured for Content Server. Are you using OTDS? If so, I believe the RCS/OTDS Authentication service provides similar impersonation methods as the CWS authentication service does.
J
yes i am using OTDS / RCS. In our case it is an OpenText xECM infra structure (Content Server 10 CU13 xECM 10 SP2).
in our Java WebClient we are using the same authentication logic as in the lltreeview sample, means we are authenicate via RCS.with OTDS. For simplicity i have also tried directly within lltreeview sample with no luck (see attached code snippet) and mygetImpersonateUser method here:
public static String getImpersonateUser( URL location, String token, String userName)throwsException{Authentication endpoint = getAuthenticationService( location );setSoapHeader( (WSBindingProvider) endpoint, token );return endpoint.impersonateUser(userName);}
My created node is still created with the origin user.
I will additionally create a ticket as Kyle suggested.
Thanks, Günter
yes i am using OTDS / RCS. In our case it is an OpenText xECM infra structure (Content Server 10 CU13 xECM 10 SP2.
in our Java WebClient we are using the same authentication logic as in the lltreeview sample, means we are athenicate via RCS.with OTDS. For simplicity i have also tried directly within lltreeview sample with no luck (see attached code snippet) and mygetImpersonateUser method here:
Hi Appu,
yes, origin user is Admin, hence SA is not an issue here.
Thanks,
Günter
I think you should try what Kyle has said approach OT support but if you are feeling yup to do some debugging some more help and pointers
I have noticed that keeping logs or builder when doing WSAPI is very good if you arenot getting much of examples/help from OTso there was somebody who wanted to do impersonation so I wrote this a while back it is C# https://knowledge.opentext.com/knowledge/cs.dll?func=ll&objaction=overview&objid=34399600
so put logs and see if you are even hitting the impersonation code in livelink because my thought tells me that the RCS stuff is just a client to livelink.
What I am trying to say is basically if the impersonation does not happen you would get errors. In your case you are in as admin
Which should have worked, but I can’t understand the part where you create the node with the impersonated token.
Secondly I have very less need to work with java and I don't use RCS/OTDS although I am being forced to so one of these days
But a lot of users contact me for examples so I base all my java examples on an excellent Brad Ceballo sample
That was a life savior to me because there was one really good example in Java .I try to stay away from the
LLTree stuff because it is way too much code that I can’t understand.
My attempts at learning to do this with Java is here
http://appukili.wordpress.com/2013/06/30/is-there-a-recordsmanagement_service-object-present-in-web-service/
what I did was re-purpose Brads's for a RM function (90 % of what he wrote is there still) but he already had code to do impersonation or you could try to find the original example it is nested somewhere in this forum
thanks a lot for your help. It is not a problem with the called ImpersonateUser function at CS side; it does the impersonation of my user as it should do and returns a valid token. At at Java site i am then setting this token also to the soapheader too before i then calling "createFolder". Again at Content Server Site i see that the feature "_Impersonate" user is not defined and as a result the folder is created with orgin user. I am pretty sure that the core reason is the deployment under RCS/OTDS and mybe also the versions i am using: Content Server 10, CU13 with xECM 10 SP2.
I have the strong feeling that this kind impersonisation has either broken with the current versions, not supported anymore in this way or has to be done in another way .
I have already opened a ticket for this at OTCS.
i have solved this by myself: For RCS/OTDS one has to use “getTicketForUser()” instead of ”ImpersonateUser()”. Below is my sample code. Note: I have done this within the lltreeview sample, to simply and easily reusing already existing WebServiceUtlis methods.
try {
String server = http://localhost:8080 ;
String user = "otadmin@otds.admin" ;
String password = " pass" ;
// OTDS-Authentication Service
String urlString= server + "/ot-authws/services/Authentication?wsdl" ;
URL baseUrl = com.opentext.ecm.services.authws.AuthenticationService. class .getResource( "." );
URL myServiceURL3 = new URL(urlString);
URL uAuthService = new URL(baseUrl, urlString);
com.opentext.ecm.services.authws.AuthenticationService myAS = new com.opentext.ecm.services.authws.AuthenticationService(uAuthService,
new QName( "urn:authws.services.ecm.opentext.com" , "AuthenticationService" ));
com.opentext.ecm.services.authws.Authentication authPort = myAS.getAuthenticationPort();
// login into OTDS
String token0 = authPort.authenticate(user, password);
fOTAuth = new OTAuthentication();
fOTAuth .setAuthenticationToken( token0 );
//#######################################################
// impersonate a user with OTDS
String impuser = "ggiebel@RSH" ;
String otressourceid = authPort.getResourceId();
// set SoapHeader
WebServiceUtil.setSoapHeader( (WSBindingProvider) authPort, token0 );
// to impersonate a user with OTDS we have to use getTicketForUser String impToken = authPort.getTicketForUser(impuser, otressourceid);
fOTAuth .setAuthenticationToken( impToken );
//################################################################# // get the appropriate webservice with the correct token fDocMan = WebServiceUtil.getDMService(
new URL( WebServiceUtil.getServiceLocation( fDefaultCwsUrl , "DocumentManagement" ) ),
impToken );
((BindingProvider) fDocMan ).getBinding().setHandlerChain(WebServiceUtil.getHandlers());
// Create a folder as impersonated user
Node otdscsNode = fDocMan .createFolder(2000, "myImpersonateFolder1" , null , null );
return ;
}
Very nice Gunter and thanks for sharing your find.It will help somebody along the way in your shoes.
Some further information here. Each time a request is made, the 'OTAuthentication' header is returned with every response from the server, and the client must use the updated value on subsequent requests. Sample code :
Node pws1 = fDocMan.getRootNode("PersonalWS"); Node pws2 = fDocMan.getRootNode("PersonalWS"); String otressourceid ="1e86d23b-ccae-4be7-96eb-ee5c2b6f8dc8"; otressourceid = fAuthService.getResourceId(); WebServiceUtil.setSoapHeader( (WSBindingProvider) fAuthService, token ); token = fAuthService.getTicketForUser("enc1@otds.nosynch", otressourceid); System.out.println("Token enc1: " + token); fOTAuth.setAuthenticationToken(token); for( javax.xml.ws.handler.Handler h : WebServiceUtil.getHandlers() ) { if( h instanceof RCSAuthenticationHandler ) { ((RCSAuthenticationHandler)h).ResetAuthHeader(); } } WebServiceUtil.setSoapHeader( (WSBindingProvider) fDocMan, token ); Node pws3 = fDocMan.getRootNode("PersonalWS"); Node pws4 = fDocMan.getRootNode("PersonalWS"); ------------------------------------------------------------ Pws1 and pws2 contain the information of the personal workspace of the admin user. Pws3 and pws4 contain the information of the personal workspace of the impersonated user. The attached RCSAuthenticationHandler writes out the used ticked to the console.