IBM Support

JR48513: BULK CLAIM TASKS BY A USER THAT IS NOT AUTHORIZED DOES NOT RETURN AN ERROR

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • This interim fix corrects multiple interrelated issues in the
    REST API.
    

Local fix

  • n/a
    

Problem summary

  • The following issues are solved:
    1. Calling the claim REST API repeatedly, the wrong error number
    and message is returned.
    
    2. Calling the bulk claim REST API by a user that is not
    authorized does not return an error.
    
    3. Calling the actions REST API returns action ACTION_INVITE
    even if the user is not authorized to invite.
    

Problem conclusion

  • 1. If an already claimed task is claimed again by an authorized
    person, then error CWTBG0549E
    (exception com.ibm.bpm.wle.api.NotAuthorizedActionException) is
    issued. This result is wrong, instead, with this interim fix,
    error CWTBG0014E (exception
    com.ibm.bpm.wle.api.WrongStateException) is issued.
    
    2. The claim REST API honors the authorizations correctly with
    this interim fix. If the bulk claim REST API is called by a
    user that is not authorized, the correct error message is
    returned.
    
    3. With this interim fix, the actions REST API returns the
    correct list of actions. ACTION_INVITE is returned if the
    calling user is authorized and the task is in the expected
    state.
    
    FIX AVAILABILITY:
    iFix for 8.5.0.1 is/will be available on Fix Central; search for
    APAR JR48513 at http://www.ibm.com/support/fixcentral/
    
    When obtaining any of the above fixes, be sure to download the
    accompanying readme, for itself, and any prerequisite fixes, and
    review them thoroughly.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR48513

  • Reported component name

    BPM ADVANCED

  • Reported component ID

    5725C9400

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2013-11-15

  • Closed date

    2014-05-07

  • Last modified date

    2014-05-07

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    BPM STANDARD

  • Fixed component ID

    5725C9500

Applicable component levels

  • R850 PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSFTDH","label":"IBM Business Process Manager Standard"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
07 May 2014