APAR status
Closed as program error.
Error description
The login implementation is done using Trust Association interceptor (TAI) class. In normal login, first TAI is called to authenticate the user and then personalization is called based on the user ID and user role stored in session via TAI class and personalization object is initialized in the session object. In case of session timeout, if the user clicks on any link, the session timeout page is displayed to user but on the server side the new session gets created and personalization is called by itself in turn, populating the personalization object in the new session. When the user logs in again, TAI is called but personalization is not called after TAI and the previous session is picked up for that user with the old personalization object due to which all the (wrong) links become visible to the user. Opened for release 6104
Local fix
Problem summary
The login implementation is done using Trust Association interceptor (TAI) class. In normal login, first TAI is called to authenticate the user and then personalization is called based on the user ID and user role stored in session via TAI class and personalization object is initialized in the session object. In case of session timeout, if the user clicks on any link, the session timeout page is displayed to user but on the server side the new session gets created and personalization is called by itself in turn, populating the personalization object in the new session. When the user logs in again, TAI is called but personalization is not called after TAI and the previous session is picked up for that user with the old personalization object due to which all the (wrong) links become visible to the user.
Problem conclusion
Changed redirect handling. Manual Steps: None Platform Specific: This fix applies to all platforms. PM35657 is part of Cumulative Fix 13 - available on Fix Central. Portal 6.1.0.3 / 6.1.5.0: http://www.ibm.com/eserver/support/fixes/fixcentral/swgquickorde r?apar=PM33723&productid=WebSphere%20Portal&brandid=5 Portal 6.1.0.4 / 6.1.5.1: http://www.ibm.com/eserver/support/fixes/fixcentral/swgquickorde r?apar=PM33732&productid=WebSphere%20Portal&brandid=5 Portal 6.1.0.5 / 6.1.5.2: http://www.ibm.com/eserver/support/fixes/fixcentral/swgquickorde r?apar=PM33742&productid=WebSphere%20Portal&brandid=5 You may need to type or paste the complete address into your Web browser.
Temporary fix
Comments
APAR Information
APAR number
PM35657
Reported component name
WEBSPHERE PORTA
Reported component ID
5724E7600
Reported release
610
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2011-03-25
Closed date
2011-04-14
Last modified date
2011-04-14
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBSPHERE PORTA
Fixed component ID
5724E7600
Applicable component levels
R610 PSY
UP
R615 PSY
UP
R61C PSY
UP
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSHRKX","label":"WebSphere Portal"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1","Line of Business":{"code":"LOB31","label":"WCE Watson Marketing and Commerce"}}]
Document Information
Modified date:
21 December 2021