Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Authenticating from a custom-menu item in TS 5.0.2
fiquebem
We're developing a JSP/Java application to be invoked from the TS GUI as a custom-menu item. We are still on TS 5.0.2. If we had FormAPI, we might not have taken that (custom application) route.
We are thinking of redirecting from a CGI (since the custom-menu item must point to either a CGI or an HTML file) to a JSP on a separate application server running on the same machine. I'll pass the TS username, the workarea, etc., to the JSP (or perhaps just the "sessionID").
I was thinking of using the TeamSite command-line tools to, for example, create and invoke a workflow job from the said application (and bypass the OpenAPI can of worms). However, someone here pointed out that a hacker could forego authentication altogether by addressing the JSP directly.
So I started looking at the IWAUTH cookie. In my test JSP, I'm invoking request.getCookies() but, alas, it only returns one cookie, namely, jsessionid.
I should be able to get the IWAUTH cookie -- what am I doing wrong; how does TeamSite get it when I type-in a URL? Via OpenAPI issuing HTTP responses/requests behind the scenes?
I never used OpenAPI before; I tried the sample IWAccessTest0.java today. It worked fine. Then I added some code copied from a posting (to check whether IWAUTH was valid). I got:
IWAccessService accSvc = (IWAccessService)IWServiceLocator.locate("IWAccessService");
^
IWAccessTest0.java:121: cannot resolve symbol
Looks like "IWServiceLocator" is not in OpenAPI 1.0.
I also got an error for:
String cookieValue = getCookie("iwauth");
Where the heck is the getCookie() method (pardon my naivete)? It doesn't seem to be in HttpServletRequest.
Anyway, with only OpenAPI 1.0, will I be able to get the IWAUTH cookie and check for its validity (from a JSP)? Recall that the JSP will be running on a different servlet engine. What ungodly classpaths/import strings will I need? Or can I just attach "rmi://host/" in front of each and every token the compiler complains about? Incidentally, don't I need to specify a port after the host above?
What other options do I have to authenticate from that application (short of prompting the user for his password)? Write/read a temporary "credentials" file on the TS box, as someone mentioned, and then expired it? Sigh ...
Unfortunately, we're pressed for time too. We have to complete our application in a couple of weeks; upgrading TS is months away.
Thanks for any feedback!
S.
Find more posts tagged with
Comments
There are no comments yet