Allowing unauthenticated users access to gatewayed pages - problem

Hi,
I was trying to allow the Guest user access to a specific gatewayed page. For this, I followed the instructions posted here: [ALUI 6.1 Anonymously Access Gatewayed Page|http://forums.oracle.com/forums/thread.jspa?threadID=902777&tstart=0].
But when I try to access that gatewayed page as guest, the portal throws a permissions exception several times in the process, followed by a redirect to the SSO.
The curious thing about this is that the exception says that "Current User does not have sufficient permission to object with id = 2". That object is exactly the Guest user object!
There must be something wrong in my setup, but I can't figure out what it is.
Below is the exception. Any idea?
6-25-2009 9:42:45.207 Warning Core ********OEL4.5.1.root [ACTIVE] ExecuteThread: '1' for queue: 'weblogic.kernel.Default (self-tuning)' com.plumtree.server.impl.core.PTBase *** PTBase.ThrowException *** (-2147024891) Current User does not have sufficient permission to object with id = 2
com.plumtree.server.marshalers.PTException: -2147024891 - Current User does not have sufficient permission to object with id = 2
at com.plumtree.server.impl.core.PTBase.ThrowException(PTBase.java:86)
at com.plumtree.server.impl.core.PTBaseObjectManager.VerifyObjectAccess(PTBaseObjectManager.java:1638)
at com.plumtree.server.impl.core.PTBaseObjectManager.Open(PTBaseObjectManager.java:769)
at com.plumtree.server.impl.community.CommunityInfoCacheEntry.Initialize(CommunityInfoCacheEntry.java:90)
at com.plumtree.server.impl.community.CommunityInfoCache.InternalCreateObject(CommunityInfoCache.java:75)
at com.plumtree.server.impl.core.PlumtreeObjectCache.FindOrCreateObjectInsecure(PlumtreeObjectCache.java:181)
at com.plumtree.server.impl.core.PlumtreeObjectCache.FindOrCreateObjectCheckSecurity(PlumtreeObjectCache.java:223)
at com.plumtree.server.impl.community.CommunityInfoCache.FindCommunitySecured(CommunityInfoCache.java:135)
at com.plumtree.server.impl.community.PTCommunityInfo.GetSecuredCommunityInfoCacheObj(PTCommunityInfo.java:712)
at com.plumtree.server.impl.community.PTCommunityInfo.<init>(PTCommunityInfo.java:61)
at com.plumtree.server.impl.community.PTCommunityManager.CachedOpenCommunityInfo(PTCommunityManager.java:584)
at com.plumtree.server.impl.portlet.providers.CSPPortletProvider.GetCanSetCommunity(CSPPortletProvider.java:1289)
at com.plumtree.server.impl.portlet.providers.CSPPortletProvider.GetContentInternal(CSPPortletProvider.java:1114)
at com.plumtree.server.impl.portlet.providers.CSPPortletProvider.GetContent(CSPPortletProvider.java:926)
at com.plumtree.server.impl.webservice.PTGadgetGateway.GetContentInternal(PTGadgetGateway.java:318)
at com.plumtree.server.impl.webservice.PTGadgetGateway.GetContent(PTGadgetGateway.java:352)
at com.plumtree.portalpages.browsing.gateway.GatewayControl.CheckActionSecurityAndExecute(GatewayControl.java:264)
at com.plumtree.uiinfrastructure.interpreter.filter.utils.GatewayHandlers.HandleGatewayRequest(GatewayHandlers.java:232)
at com.plumtree.uiinfrastructure.interpreter.filter.GatewayFilter.PreFilter(GatewayFilter.java:54)
at com.plumtree.uiinfrastructure.interpreter.Interpreter.DoPreFilter(Interpreter.java:1786)
at com.plumtree.uiinfrastructure.interpreter.Interpreter.HandleRequest(Interpreter.java:234)
at com.plumtree.uiinfrastructure.interpreter.Interpreter.DoService(Interpreter.java:155)
at com.plumtree.uiinfrastructure.web.XPPage.service(XPPage.java:306)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:820)
at weblogic.servlet.internal.StubSecurityHelper$ServletServiceAction.run(StubSecurityHelper.java:226)
at weblogic.servlet.internal.StubSecurityHelper.invokeServlet(StubSecurityHelper.java:124)
at weblogic.servlet.internal.ServletStubImpl.execute(ServletStubImpl.java:283)
at weblogic.servlet.internal.TailFilter.doFilter(TailFilter.java:26)
at weblogic.servlet.internal.FilterChainImpl.doFilter(FilterChainImpl.java:42)
at com.plumtree.binarygateway.BinaryGatewayFilter.doFilter(BinaryGatewayFilter.java:71)
at weblogic.servlet.internal.FilterChainImpl.doFilter(FilterChainImpl.java:42)
at weblogic.servlet.internal.WebAppServletContext$ServletInvocationAction.run(WebAppServletContext.java:3393)
at weblogic.security.acl.internal.AuthenticatedSubject.doAs(AuthenticatedSubject.java:321)
at weblogic.security.service.SecurityManager.runAs(Unknown Source)
at weblogic.servlet.internal.WebAppServletContext.securedExecute(WebAppServletContext.java:2140)
at weblogic.servlet.internal.WebAppServletContext.execute(WebAppServletContext.java:2046)
at weblogic.servlet.internal.ServletRequestImpl.run(ServletRequestImpl.java:1366)
at weblogic.work.ExecuteThread.execute(ExecuteThread.java:200)
at weblogic.work.ExecuteThread.run(ExecuteThread.java:172 <ptLogMsgEnd>
Thank you

i'm not saying this is what it is...(hopefully its not), but there are certain folders that you absolutely can't remove the everyone user from... i think Plumtree is an expert on this.
have you been 'locking down' your portal recently?

Similar Messages

  • Way to allow the user access to the saved lists of this Z report

    We have a Z report that we want to run at midnight each Sunday and then view the output/layout first thing Monday morning. We can schedule the report to run but it appears that the only way we can save the output as a 'file' for later viewing is by using the "Save with ID" option, which puts the output into a SAP 'saved list'.
    The problem with this is that it doesn't appear to be possible to access that list from the Z-report - it would appear that you have to go into SQ01 and use the 'saved list' button. This means giving the Z- report user access to SQ01 as well as Z-report, which, for security (SOD) reasons we don't want to do.
    We can run the report in foreground with the output option "File store" and save the output as a file to a specified location,. But this option doesn't appear to be available when the report is scheduled as a background job. If this is done, the background job runs but there's no output anywhere, as far as we can tell.
    So what want is to run the report in background but with the output option 'File store' or equivalent (i.e. an output stored somewhere that the report user can view). Is this not possible, or have we missed something in setting up the report run?
    Or is there a way to allow the user access to the saved lists of this Z report without giving them T-code SQ01?
    Thanks

    Hi !
    I just wonder if the answer from Varishtb below did solve your propblem.
    I have exactly the same problem as you. I also want to be able to look at the saved list without using the sq01.
    If you solved it I will be grateful to get the solution.
    regards Lars
    answer:
    You can call the infoset query directly from a transaction code. There's
    no need to copy it as a 'Z-report' (or as a custom report). In fact,
    everytime you're copying an infoset query to a report, you're calling
    for problems the next time you face an upgrade. (That is because SAP
    changes the internal logic used to handle the infosets queries from
    version to version)
    We're using some infoset queries and they work fine this way.

  • In Firefox 4 the dropdown menu next to the forward button in the Navigation Toolbar that allowed the user to select another page in the history to go back to is gone. Why?

    In Firefox 3, the user could access a dropdown menu by hovering over a small black arrow next to the forward arrow in the Navigation Toolbar. This allowed the user to go to earlier pages in the browser history, rather than using the back button to go to the immediate previous page.
    After updating to Firefox 4, this menu disappeared. Was it moved? Was it removed?
    I found this feature to be very useful. Why was it changed?
    Nick

    There are two ways to get this: (1) Hold the back button until the menu appears (2) Right click the back button. See the screenshot below for reference.

  • MobileMe Gallery - allowing multiple users access

    Hi,
    I have a simple question - can allow more than one user access to a hidden MobileMe Gallery?
    I seem to be able to choose only one name from a drop-down list. I'd like to allow two people access to my gallery. Is this possible?
    Thanks,
    :-Joe

    Joe:
    Give the same name and password to both viewers.
    TIP: For insurance against the iPhoto database corruption that many users have experienced I recommend making a backup copy of the Library6.iPhoto (iPhoto.Library for iPhoto 5 and earlier) database file and keep it current. If problems crop up where iPhoto suddenly can't see any photos or thinks there are no photos in the library, replacing the working Library6.iPhoto file with the backup will often get the library back. By keeping it current I mean backup after each import and/or any serious editing or work on books, slideshows, calendars, cards, etc. That insures that if a problem pops up and you do need to replace the database file, you'll retain all those efforts. It doesn't take long to make the backup and it's good insurance.
    I've created an Automator workflow application (requires Tiger or later), iPhoto dB File Backup, that will copy the selected Library6.iPhoto file from your iPhoto Library folder to the Pictures folder, replacing any previous version of it. It's compatible with iPhoto 6 and 7 libraries and Tiger and Leopard. Just put the application in the Dock and click on it whenever you want to backup the dB file. iPhoto does not have to be closed to run the application, just idle. You can download it at Toad's Cellar. Be sure to read the Read Me pdf file.
    Note: There's now an Automator backup application for iPhoto 5 that will work with Tiger or Leopard.

  • Allow a user access to start and stop a particular service in Solaris 11 using RBAC controls

    So, using svcbundle I created a service called "oracle" that starts and shutdown a db. I'm aware of how to grant RBAC access to be a "service operator" to be able to control start/stop ALL services. But I'd like to grant a user access to start and stop JUST this service.
    in this document on page 15, it states that it's possible to do this kind of granularity but doesn't explain how to do it step by step.
    how does one achieve this?
    thanks.

    You need to add a property group such as
    <property_group name='general' type='framework'>
      <!-- to start stop oracle -->
      <propval name='action_authorization' type='astring'
      value='solaris.smf.manage.oracle' />
    </property_group>
    Then add the solaris.smf.manage.oracle authorization to the user profile.
    As an example, see Less known Solaris features: RBAC and Privileges - Part 2: Role based access control - c0t0d0s0.org

  • Allow multiple users access to iphoto

    I would like to allow multiple users on same computer to access Iphoto files.  What setting changes need to be made?
    Thanks
    mfandml

    iPhoto: Sharing libraries among multiple users...
    http://support.apple.com/kb/HT1198

  • With iTunes on an external hard drive can I allow multiple users access?

    I keep my iTunes library on my time capsule since it is far to large to keep on my hard drive.  We have always had only one user account.  Now that my daughter is onl enough to use the computer on her own I set up her own account so that I could enact parental controls, but I noticed her iTunes is empty.  Can I have it access the library on the time capsule.  If I do this do I run the risk of her deleting files?  If I let her create her own library isn't it just a bunch of duplicate files eating up space?  Any help is greatly appreciated!  Thanks !

    PhoenixR wrote:
    If I do this do I run the risk of her deleting files?
    yes.
    If I let her create her own library isn't it just a bunch of duplicate files eating up space?
    yes, but it would be safer.

  • Allowing a user access to all calendars in his OU

    Hi Everyone.
    I have a hosted exchange environment (Meaning we have many little companies that buy mailboxes from us, and each one has its own OU under the main OU called Hosting.Local)
    One of our bigger clients has about 250 mailboxes in his OU, the CEO wants permission to view the calendars of all users in his OU.
    I was wondering, is there a way to do it with a script to grant him this access or must I really do it manually for each mailbox?
    Hoping for a quick response.

    Hi,
    We should edit the
    Get-Mailbox to get a list of all the mailboxes in your organization in that OU.
    The script should be like this:
    $allmailbox = Get-Mailbox -OrganizationalUnit “OUname” -Resultsize Unlimited
    Foreach ($Mailbox in $allmailbox)
    {Set-mailboxfolderpermission –identity ($Mailbox.alias+':\calendar’) –user Default –Accessrights AvailabilityOnly}
    Best Regards.
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Lynn-Li
    TechNet Community Support

  • Receiving a FAX or allowing PC user access to idisk file

    Hello everyone,
    I work with someone who uses a PC and Outlook Express and I need to be able to receive her appointment schedule in some manner. I have Verizon DSL, I followed the Help instructions to set up my ibook to receive a fax and connected a cable from the modem on the ibook to the modem connection on my power strip but when she sends me a fax my ibook doesn't recognize it and stays in idle mode. I tried to set up a place on my idisk that she could put the schedule but it puts some photos in there from another homepage that I have and I can't figure out how she can put anything there.
    Any assistance would be greatly appreciated. We have resorted to snail mail arrrrrgh!!
    Thanks,
    Anna

    I know, that would be simple but apparently Outlook Express doesn't allow her to do that. She can print it and that's why we thought setting my ibook up to receive a fax would work.
    Thanks anyway,
    Anna

  • My email wont allow me to access from home page

    on the bottom of my new iphone 5s, my icon for my email is showing i have unread messages. When i push the tab, it goes to ICloud at the top but the mail button is faded. How do I access my email from this point?

    on the bottom of my new iphone 5s, my icon for my email is showing i have unread messages. When i push the tab, it goes to ICloud at the top but the mail button is faded. How do I access my email from this point?

  • Can multiple XP users access the same iTunes library?

    Because I'm having a REALLY hard time getting that to work at all. I've moved my entire iTunes folder into 'Shared Documents' so that all users should be able to access it and changed the option in iTunes Preferences to the correct 'all users' path, but iTunes still tries to find the info in 'my' (sal's) documents instead of 'all.'
    Anyone figure this out, or does it somehow break the EULA and isn't supported? The wife and I just want to use the same library since we're on one computer. Seems silly to not allow a user with admin rights to allow other users access.
    Thanks,
    Sal
      Windows XP  

    Sal,
    As this article in the Apple Knowledge Base explains the trick is to move the iTunes Music folder, not the entire iTunes folder, to "a publicly accessible location" and I believe they mean to suggest C:\Documents and Settings\All Users\Documents\My Music as a good place.
    It is important that the iTunes Library files remain in Sal's Documents and Sal's Wife's Documents.

  • Accessing Enterprsie login page?

    Our DBA installed patch "XDO/ORACLE XML PUBLISHER CORE ROLLUP PATCH 5.6.2, # 5097966".
    Does that allow me to access the Enterprise pages? If so do i need a special responsiblity and what is the URL? Or is there another patch for this application?
    I don't know if i'm totally missing something here, the 5.6.2 doc B25951-01, doesn't have much other then access the URL your sys admin gives you.
    Thanks,
    Jeremy

    Hi Sreeram,
    The error you are seeing in the log files is caused by the unconfigurerd default iDoc listener that is supplied with xMII, so that is not the likely cause of the error you are seeing.  I would recommend you submit your question through the SAP Support Portal as this appears to be a case that could be resolved much more quickly by the Support team.
    Kind Regards,
    Diana Hoppe

  • Web Site Display Language - Allowing the user to chose the language

    I have created a web site that allows the user to display the page in the language of the users choice.
    Windows Internet Explorer and FireFox both allow the user to select a language option, and the web page will display the text in that language.
    Safari on the Mac does not allow the display to be changed.
    I have used the System Preferences - International option to select the language that I would like to use. The operating system menus and other options display as expected.
    Safari does not.

    I have created a web site that allows the user to display the page in the language of the users choice.
    What is the website?

  • Problems to restrict access to a page when the user belong to more than 1 group

    I have realized that Dreamweaver on a coldfusion document only works fine when the user only belongs to a single group, this is because the code supplied by dreamweave when you use the option "Restrict access to a page" at "Server behaviors" it assumes that the user only have one group as you can see on this line created automaticly by dreamweaver:
    <cfif MM_Username EQ "" OR MM_UserAuthorization EQ "" OR ListFind("admin",MM_UserAuthorization) EQ 0>
    MM_UserAutorization has the value of the field assigned for the list of groups or levels, as you can see it could work if we reverse the parameters of the listfind function but the problem would be if we grant the access to more than one group because the sentence would be like this:
    <cfif MM_Username EQ "" OR MM_UserAuthorization EQ "" OR ListFind("Admin,Manager",MM_UserAuthorization) EQ 0>
    so both paramethers are lists therefore no user will get access to the page.
    I am trying to make a work around to fix this problem but I don't know how to get the name of the page since the Application.cfc so I can validate the access to this page against tables on my database.
    Does someone have a work around or a tip how to fix this problem?
    Thanks in advance.
    AG

    Seems like you have a problem with your group names.ctxLdap.modifyAttributes(groupName,member);Ensure that the value of your variable groupName is a a valid distinguished name.
    Note that an OU (organizationalUnit) is not a group. You do not add users to OU's, you create users in OU's.

  • Help! My IE8 users can no longer access their wiki pages after upgrade to Lion.

    I upgraded my SL server to Lion without checking the browser requirements for the new Wiki server.  My users access the wiki via a Windows 2003 Terminal Server which is stuck on IE8, can't install IE9 on it.  I push out the home page URL via group policy and now everyone is getting the "unsupported browser" message.  Is there any way to allow them access with IE8?  They don't actually update the wiki, that can be done with a compatible browser no problem but they need to be able to click on links.  Do I just need to set up a separate website for them?

    Anybody got this?
    I've got 2 drives, and  only the bottom one works after the 10.7 rollout? Doesn't appear that the other one is even recognized in the system profiler anymore.
    Surely there's someone that  knows wth is going on here...?

Maybe you are looking for

  • "Alternate path to a folder containing the installation package 'iTunes.msi'"

    Trying to upgrade my iTunes for my new IPod Touch(32GB). It needs a newer version than I have. When running the installer, it must remove the old iTunes first, I assume.  This is what I receive: "The feature you are trying to use is on a network reso

  • Full Pages with Zero Margins

    I'm trying to use Pages to format and print labels for various products on a Phaser 8200 printer. Previously I had used Word, but I'm trying to convert over to Apple software. The problem I'm having is that I format the labels as tables, with the tab

  • Transactional replication with 1 publisher 2 subscribers in SQL 2012 SE

    I have a setup of transaction replication between one publisher and subscriber in the Same server.Now, I need to add a new subscriber to the existing publisher. So publisher database name is DB_A and Subscriber 1 name is DB_B. So the new subscriber w

  • Ale audit steps

    Hi, Can anybody please explain ale audit steps. 1. i am sending idocs from send1 rece1. how i can i know the status of outbound idocs using ale audit i want to know the process behinds this.

  • How do I re-install Adobe Encore?

    I am a Creative Cloud client and today I uninstalled Premier Pro CS6 & CC because I was having problems with Premier Pro CC (2014). Problem is i have lost Adobe Encore, any idea how I get it back?