IBM Support

IZ66908: POST MESSAGE TO RETURN_TO URL SHOULD USE QUERY STRING IF POSSIBLE

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When sending an indirect message to an OpenID partner (typically
    the
    response from an OP to an RP), if the URL that the message is to
    be sent to contains query string parameters we currently ALWAYS
    move these query-string parameters to FORM input parameters.
    
    This actually breaks interoperability with the DOTNET RP
    implementation.
    Section 11.1 of the OpenID 2.0 spec requires
    these parameters to remain as part of the URL.
    

Local fix

Problem summary

  • In this defect we will check the size of the target URL, and if
    it's length
    is not too long, we will keep that URL intact in the POST,
    otherwise
    we will default to existing behaviour and move all the query
    string
    parameters to the POST body.
    
    CMVC Defect:
    IZ66908
    

Problem conclusion

  • The fix for this APAR will be contained in the following
    maintenance packages:
    
    | fix pack | 6.2.0.3-TIV-TFIM-FP0003 |
    

Temporary fix

Comments

APAR Information

  • APAR number

    IZ66908

  • Reported component name

    TIV FED ID MGR

  • Reported component ID

    5724L7300

  • Reported release

    620

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2009-12-16

  • Closed date

    2009-12-16

  • Last modified date

    2009-12-16

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TIV FED ID MGR

  • Fixed component ID

    5724L7300

Applicable component levels

  • R620 PSY

       UP

[{"Business Unit":{"code":"BU029","label":"Software"},"Product":{"code":"SSZSXU","label":"Tivoli Federated Identity Manager"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"620"}]

Document Information

Modified date:
29 December 2021