Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Calling iwjobc when user is not master
Cat
Hi,
I need to call iwjobc from a perl script but the script is not run by master users and so of course this does not work as iwjobc can only be run by a master. Is there anyway around this?
I have read the forums and one possibility was to setuid iwjobc but of course that isn't an ideal solution.
Thanks
Cat
Find more posts tagged with
Comments
Migrateduser
It doesn't make sense that a CLT is related to role. What does it return when you try to execute it and it doesn't work?
Dave Smith
Sr. Software Engineer
Nike, Inc.
(503) 671-4238
DavidH.Smith@nike.com
Cat
The error I get is 'You must be a master to run iwjobc.'
Migrateduser
Oh, well don't I feel like an idiot. That doesn't seem right. I'm sure someone from Interwoven will jump in on this. Sorry I was such a moron.
Dave Smith
Sr. Software Engineer
Nike, Inc.
(503) 671-4238
DavidH.Smith@nike.com
Migrateduser
Add the user running the script (SYSTEM? ROOT? Web Impersonator? whoever?) to the masters.uid file (harder if you are using LDAP).
Cat
The perl script is being run from a tpl and so it will be editors and administrators running this. Unfortunately we can't add all the users to the master.uid file as they would then gain access to all of our 180 sites within teamsite ;-)
Migrateduser
What if you tried changing the owner of the script that calls iwjob to someone in the masters.uid file? Then you could set the set-uid bit on the script (chmod 4755) and it will always execute as that user. You may run into some perl "taint" issues, but these are usually easily resolved. I know this works on Unix, but not sure how or if it can be done on Windows.
Dave Smith
Sr. Software Engineer
Nike, Inc.
(503) 671-4238
DavidH.Smith@nike.com
Migrateduser
You can call Java from Perl and have java use OpenAPI. That is not as complex as it looks/sounds, other than somehow you would have to get the session ID of the user to the Perl to pass to the Java to access TeamSite. Here is some cut and paste that may point you in the right direction.
import com.interwoven.api.access.IWAccessorAuthentication;
import com.interwoven.api.access.IWAccessService;
import com.interwoven.api.service.IWService;
import com.interwoven.api.workflow.IWWorkFlow;
import com.interwoven.api.workflow.IWWorkFlowService;
String strRMI = "rmi://" + /* hostname */ + ":1099/";
IWAccessService objIWAccessService = (IWAccessService) IWService.locate( strRMI + "IWAccessService" );
IWAccessorAuthentication objIWAccessorAuthentication = IWAccessorAuthentication.createFromString( objIWAccessService, /* session id string */);
IWWorkFlowService objIWWorkFlowService = (IWWorkFlowService) IWService.locate( strRMI + "IWWorkFlowService" );
objIWWorkFlowService.getContext().setAccessorAuthentication( objIWAccessorAuthentication );
IWWorkFlow objIWWorkflow = IWWorkFlow.createFromXMLString( objIWWorkFlowService, /* job xml */, null );
if ( objIWWorkflow.isValid( objIWWorkFlowService ))
{
// job created
}
else
{
// job not created
}
1736.pdf
mogoo
If this process is run via a workflow, just make the owner of the task that deals with iwjobc someone that does have master status. You'll have to View All Jobs to see it running, but it will run properly if you do it that way...
maureen
Cat
Unfortunately it is not run through a workflow - the perl script that calls iwjobc is run from a presentation template.
Cat
I have tried this and unfortunately I still get the same error. Coudl this be because the script is originally kicked off by a TPL?
Migrateduser
That I can't answer. I really don't understand why it wouldn't work if you have the setuid bit set and the owner of the script assigned to someone in your master.uid file. It would be nice if someone from Interwoven jumped in to help with this.
Dave Smith
Sr. Software Engineer
Nike, Inc.
(503) 671-4238
DavidH.Smith@nike.com
InputQueue_1.png
InputQueue.png
sajiddc
I can see one reason as to why the user running the iwjobc command has to be a master.
Allowing non-master users (assumed high admin. privileges) to run iwjobc is a security hole. For example, a user could create an arbitrary XML job spec that runs an external task as "root" specifying virtually any script he/she wanted.
Migrateduser
That wasn't the question. The question was why, even when the script was owned by a master and the setuid bit was set to run the script as the script owner, it still didn't work. But thanks for playing.
Dave Smith
Sr. Software Engineer
Nike, Inc.
(503) 671-4238
DavidH.Smith@nike.com