IBM Support

PK66114: PORTLETS ARE NOT ADDED CORRECTLY TO APPLICATIONS/PLACES

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Portlets are not added correctly to applications/places when
    the executing user is a portal administrative user. The portlets
    are disappearing from the system later when the page is getting
    removed from the place.
    
    This is caused by having the portal administrative user in a
    place role that is not allowed to add components. The portal
    administrative user is nevertheless able to add
    components/portlets to application pages from the  portal
    administration  "Manages Pages" portlet and thereby is bypassing
    the Quickr AC checks in the UI.
    
    The low-level AI code is then doing a AC checks, finds the user
    is not in the correct role and stops the adding process.
    Unfortunetaly the used engine command is not able to give this
    information to the Quickr UI and thus leaves a broken system.
    But that is not visible to the user.
    
    This leaves the system in an inconsistent state which in the end
    leads to the removal of the wrong portlet defintion at a later
    point in time when the business component is removed from the
    application.
    

Local fix

Problem summary

  • Portlets are not added correctly to applications/places when the
    executing user is a portal admin user. The portlets are
    disappearing from the system later when the page is getting
    removed from the place. This is caused by having the portal
    admin user in a place role that is not allowed to add
    components. The portal admin user is nevertheless able to add
    components/portlets to application pages from the portal
    administration  "Manages Pages" portlet and thereby is bypassing
    the Quickr AC checks in the UI.
    The low-level AI code is then doing a AC checks, finds the user
    is not in the correct role and stops the adding process.
    Unfortunetaly the used engine command is not able to give this
    information to the Quickr UI and thus leaves a broken system.
    But that is not visible to the user.
    This leave the system in an inconsistent state which in the end
    lead to the removal of the wrong portlet defintion at a later
    point of time when the business component is removed from the
    application.
    

Problem conclusion

  • This fix is allowing the portal admin user to add the portlet
    even if he is in the wrong or no role. The AI code no longer
    does the AC check in the low-level code.
    The Quickr UI and Portal UI and Services have to ensure the
    user is allowed to do the triggered action.
    
    
    Failing Module(s):
       Composite Applications
    
    Affected Users:
       All users
    
    Version Information:
        Portal Version(s): 6.0.1.1
         Pre-Requisite(s):
          Co-Requisite(s): ---
    
        Portal Version(s): 6.0.1.3
         Pre-Requisite(s):
          Co-Requisite(s): ---
    
    Platform Specific:
       This fix applies to all platforms.
    
    A fix is available from Fix Central:
    
    http://www.ibm.com/eserver/support/fixes/fixcentral/swgquickorde
    r?apar=PK66114&productid=WebSphere%20Portal&brandid=5
    
    You may need to type or paste the complete address into your Web
    browser.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PK66114

  • Reported component name

    WEBSPHERE PORTA

  • Reported component ID

    5724E7600

  • Reported release

    60G

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2008-05-15

  • Closed date

    2008-05-29

  • Last modified date

    2008-06-11

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE PORTA

  • Fixed component ID

    5724E7600

Applicable component levels

  • R60E PSY

       UP

  • R60G PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSHRKX","label":"WebSphere Portal"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.0.1.3","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
11 June 2008