IBM Support

IT15659: OAUTH SCOPE INFORMATION BEING TRACKED BY APPLIANCE MUST BE ACCUMULATIVE WITH ITS DISTRIBUTED CACHE SUPPORT

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Gateway can be configured to use distributed storage to track
    the permission issued with its OAuth protocol support. Gateway
    records information about an *issued* delegated authorization,
    gateway currently tracks the last scope that is approved.
    
    e.g.
    When an application supports 2 scopes, scopeA, and scopeB.  The
    application can request scopeA, initiately. The application,
    subsequently, requests for scopeB, the gateway needs to track
    both scopeA and scopeB as what were given to the application.
    Without this fix, gateway only tracks scopeB, in the above
    scenario.
    

Local fix

Problem summary

  • Affected is use of OAuth.
    
    Gateway can be configured to use distributed storage to track
    the permission issued with its OAuth protocol support. Gateway
    records information about an *issued* delegated authorization,
    and incorrectly tracks the last scope that is approved only.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    IT15659

  • Reported component name

    DATAPOWER

  • Reported component ID

    DP1234567

  • Reported release

    750

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2016-06-09

  • Closed date

    2016-09-06

  • Last modified date

    2016-09-15

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    DATAPOWER

  • Fixed component ID

    DP1234567

Applicable component levels

  • R751 PSY

       UP

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateways"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"750"}]

Document Information

Modified date:
25 September 2021