IBM Support

webMethods Knowlegebase : Calling a WS from XML-RPC server ClientID and Secret can only be specified in URL

Troubleshooting


Problem

When calling a webservice that is protected and requires Client-id and Secret, these can only be specified in the URL, XML-RPC server does NOT support specifying these in the HTTP header.

This missing support is considered a security vulnerability, as having security tokens in the URL could give access to them e.g., by having them logged.

Please provide support for having these security tokens in the HTTP header.

Document Location

Worldwide

[{"Line of Business":{"code":"LOB70","label":"Z TPS"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSO27W6","label":"IBM EntireX"},"ARM Category":[{"code":"a8mKe00000000AQIAY","label":"EntireX (EXX)"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Red Hat Enterprise Linux AS"}],"Version":"10.7"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
20 March 2025

UID

ibm17227584