APAR status
Closed as program error.
Error description
Clicking and performing a modify on a folder in the Tree Pane (left Pane) does not verify if the user has Role access to the action. Performing the same action on a folder in the view Pane (right pane) does verify the role and will error if they user does not have access. Steps to reproduce. Folder Class must be controlled not stateless. Role must be added to a state in the controlled class, the Role should not have Modify Checked. Test user should be added to the role. My Class did not have a modify dialog and the DM Modify was disabled. If you have no controlled class folders in the library crate one and add it to the root folder. Log into the DM Desktop with the test user. Click on the test folder in the tree pane (left pane) to highlight it, click on the modify command. The Add Item Wizard folder pane should be displayed. Click on the Root Folder then click on the test folder in the view pane (right pane) to highlight it, click on the modify command You should see an "ERROR: User, Group [] us not listed in any roles for class [ ], state [ ]"
Local fix
Problem summary
Role checking did not occur in the Desktop folder navigation pane If users selected controlled-class folders in the Desktop folder navigation pane, role checking did not occur, so access control was not enforced. Users whose roles restricted access were able to open the folders from the folder navigation pane.
Problem conclusion
The fix is available in DB2 Document Manager v8.3 Fix Pack 10.
Temporary fix
Comments
APAR Information
APAR number
IO08855
Reported component name
DOCMGR DESKTOP
Reported component ID
5724H9000
Reported release
830
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2008-05-03
Closed date
2008-12-28
Last modified date
2008-12-28
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
DOCMGR DESKTOP
Fixed component ID
5724H9000
Applicable component levels
R830 PSY
UP
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSCXQ53","label":"Desktop"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"830","Edition":"","Line of Business":{"code":"","label":""}}]
Document Information
Modified date:
28 December 2008