IBM Support

PI93604: RESTRICTING AUTHENTICATION TOKENS

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • When using Authentication Tokens "POST
    /rest/workflow/outputProps/* needs to be manually added.
    
    Create an Application which includes Clean working space,
    Download artifacts step, Compress artifacts, Deploy artifacts
    From Product Documentation in a standalone fresh (new) 6.2.7.0
    environment with Token Restriction System Default as configured
    out of the boxMethod(ALL) /*
    Deployment works OK.
    
    Amended Token Restriction System Default of just GET
    /cli/status/getStatus*
    deployment FAILS 403
    
    In order to get a successful deployment again for the
    application
    the following Token Restriction were added
    1. POST /rest/workflow/outputProps/*
    2. GET /rest/inventory/versionByResourceAndComponent/*
    3. POST /codestation/v1/artifacts/*
    
    1) no, this was not intended to be necessary. we do have a
    whitelist of urls that the agent/plugin system use that will
    always be available. this one was missed. we'll file an apar for
    it.
    2) yes this is expected.
    3) yes this is expected.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * All end users on all supported browsers.                     *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * When using Authentication Tokens "POST                       *
    * /rest/workflow/outputProps/* needs to be manually added.     *
    *                                                              *
    * Create an Application which includes Clean working space,    *
    * Download artifacts step, Compress artifacts, Deploy          *
    * artifacts                                                    *
    * From Product Documentation in a standalone fresh (new)       *
    * 6.2.7.0                                                      *
    * environment with Token Restriction System Default as         *
    * configured                                                   *
    * out of the boxMethod(ALL) /*                                 *
    * Deployment works OK.                                         *
    *                                                              *
    * Amended Token Restriction System Default of just GET         *
    * /cli/status/getStatus*                                       *
    * deployment FAILS 403                                         *
    *                                                              *
    * In order to get a successful deployment again for the        *
    * application                                                  *
    * the following Token Restriction were added                   *
    * 1. POST /rest/workflow/outputProps/*                         *
    * 2. GET /rest/inventory/versionByResourceAndComponent/*       *
    * 3. POST /codestation/v1/artifacts/*                          *
    *                                                              *
    * 1) no, this was not intended to be necessary. we do have a   *
    * whitelist of urls that the agent/plugin system use that will *
    * always be available. this one was missed. we'll file an apar *
    * for                                                          *
    * it.                                                          *
    * 2) yes this is expected.                                     *
    * 3) yes this is expected.                                     *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Fixed in version 6.2.7.2                                     *
    ****************************************************************
    

Problem conclusion

  • Fix is provided in IBM UrbanCode Deploy 6.2.7.2
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI93604

  • Reported component name

    UC DEPLOY

  • Reported component ID

    5725M5400

  • Reported release

    627

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-02-09

  • Closed date

    2018-04-04

  • Last modified date

    2018-04-04

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    UC DEPLOY

  • Fixed component ID

    5725M5400

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS4GSP","label":"IBM UrbanCode Deploy"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"627","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
04 April 2018