Netpoint 5.96 Catalog security problem - Anyone can see other users catalog

I just had a revelation regarding the security of the catalogs.
Anyone wise enough to realize that adding ?Category=x on the address can access the catalogs of any other customers !!!!! BIG BIG PROBLEM
I will soon test if they also get the price list of that other catalog ?
Is there a way to prevent a user from SEEING other catalogs ?

Hi Shane,
thanks for that, it worked nicely.
For anyone watching this thread, he're my effort at securing the shipment.aspx page.
It is an ascx control with no visual components, that you should drop in right at the very top of the page:
<%@ Control Language="C#" ClassName="SBPageSecurity" %>
<%@ Import Namespace = "netpoint.classes" %>
<%@ Import Namespace = "netpoint.api.catalog" %>
<%@ Import Namespace = "netpoint.api" %>
<%@ Import Namespace = "netpoint.api.commerce" %>
<script runat="server">
    protected void Page_Load(object sender, EventArgs e)
       string connString =  ConfigurationSettings.AppSettings["connString"].ToString();
       NPSession s = new NPSession(this.Context, connString);
       //verify that the logged-in accountId matches the Shipment object AccountID
       int docnum = (Request["shipmentid"] == null ? 0 : Convert.ToInt32(Request["shipmentid"]));
       if (0 == docnum)
           //no doc num
           Response.End();
       else
           NPShipment shipment = new NPShipment(docnum);
           if (shipment.AccountID != s.AccountID)
               Response.End();
</script>
So basically all it does is verify that the logged in Account "owns" the document they are trying to view.
I'm sure there is room for improvement, but at least it may be a place to start for some folks.
Regards,
Steve

Similar Messages

  • I run a mac air on a single user account but multiple people using it, which is ok for the situation. All have their accounts in the apple mail app. what is missing for me is a separate password to access the mail account. otherwise anyone can see anyones

    I run a mac air on a single user account but multiple people using it, which is ok for the situation. All have their accounts in the apple mail app. what is missing for me is a separate password to access the mail account. otherwise anyone can see anyones
    Any clue, how i can add a mail account to apple mail app, but with separate password / pin to open it.
    Years ago there was a program called mail switcher which added this functionality, but thats gone.
    cheers
    Tom

    They would have to be logged in as separate users in order not to see your account in Mail. Whatever accounts put in Mail under your account will show up. All mail accounts usually have there own user and password. The only thing you can do is to remove the password from Keychain and take the account offline so you don't keep getting prompts for passwords each time it checks for mail.
    Not a great solution.
    Best way is to give the other user their own user account with their own mail and enable fast user swithcing to log between the different users if all access the computer frequently.

  • HT4798 I'm seeing the above problem, how can i open "Users&Groups" if i can't login?

    I'm seeing the above problem, how can i open "Users&Groups" if i can't login?

    If the system is associated with an Apple ID, and you know that account password, the Apple ID can be used to reset your user account password.
    Otherwise, boot into Recovery by holding down the key combination command-R at startup. Release the keys when you see a gray screen with a spinning dial.
    When the OS X Utilities screen appears, select Utilities ▹ Terminal from the menu bar.
    In the Terminal window, type this:
    resetpassword
    That's one word with no spaces. Then press return. A Reset Password window opens.
    Select your boot volume if not already selected.
    Select your username from the menu labeled Select the user account if not already selected.
    Follow the prompts to reset the password. It's safest to choose a password that includes only the characters a-z, A-Z, and 0-9.
    Select  ▹ Restart from the menu bar.
    You should now be able to log in with the new password, but you won't be able to unlock the Keychain. If you've forgotten the Keychain password (which is ordinarily the same as your login password), there's no way to recover it. You’ll need to reset your keychain in the preferences of the Keychain Access application.

  • Resource can see other resources' projects in project center

    Hi,
    In PWA I have a resource (project manager) can see other resources' projects listed in project center when he logs-in. He is in Project Managers group like other resources (Project managers) and no direct access was granted to him by Project Permissions
    and I want him to see his projects only.
    Anyone knows how to solve this problem please.
    Thanks in advance for your help.

    Hi,
    You can handle this by using RBS this is one of way doing it
    For example:
    I have 3 PMS  PM!, PM2, PM3
    In RBS
    Set like the below
    Organisation
         PM1
            Dev
         Pm2
            Dev
         Pm3
            Dev
    Go to Server Settings --> Manage Users--> Open the PM1--> In RBS set his RBS value like Organisation.PM1 same case with all.
    Please check the security categories of the project manager --> My Projects -->
    Only the below option need to be checked and uncheck the remaining.
    The user is the Project Owner or the User is the Status Manager on assignments within that project
    Users with permissions in the category where this option is selected can see projects on which they are a Project Owner or a Status Manager
    Hope this helps
    Geeth If you feel that the answer which i gave you is Helpful please select it as Answer/helpful.

  • Can see other ppl's iMacs, Time Capsules...

    I can see other people's iMacs/Time Capsules in my Shared menu in the left hand side of the finder. I have airport turned OFF. I don't use airport and connect to the internet through ethernet. I do have satelite internet. I had my Mac serviced because I thought I was being hacked - ppl who serviced Mac said that wasn't the case.
    Is this normal, to be able to see other ppl's iMacs, Time Capsules that are in your area? Even when Airport is turned off?
    This only started a couple of weeks ago when our internet was down for about a week, and the was reconnected.
    Even with my airport turned completely off, why is this happening?
    SO FRUSTRATED!

    It makes no difference whether your AirPort is turned off or not as long as your Time Capsule is connected to the Internet connection by Ethernet, you will probably continue to see other devices under the SHARED heading in the Finder.
    If you took your Mac to a hotel and connected to the Ethernet port in the room, you would also see other users under the SHARED heading. But, they cannot access your Mac or any other devices unless they have the password(s) required to do so.
    The same thing will happen if you take your laptop down the coffee place and log on there using the wireless. You will see a number of other users under the SHARED heading as well. Again, there is no problem as long as they do not have the device password for your Mac
    Other users can "see" you as well, so they too may be feeling a bit uneasy about things.
    If what you see bothers you, you need to look into a DSL or cable connection for your home or apartment.

  • How do you use Time Machine to restore a specific users account?  I can't do it from the user screen because I am not allowed.  I can't do it from the admin because I can't see other users in Time machine.

    I can't restore my user account from the users screen because I get an alert that Mac OS needs something.  I can't restore in TimaeMachine from the Admin screen because I can't see other users home folders.  What can I do?

    See Pondini's TM FAQs for starters.

  • I have rented a movie on apple tv and wish to finish it on my mac book air. When I open iTunes on my mac book air I can not see the movie in iTunes. It is an authorised device and I can see other purchases just. How do I fix it?

    I have rented a movie on apple tv and wish to finish it on my mac book air. When I open iTunes on my mac book air I can not see the movie in iTunes. It is an authorised device and I can see other purchases just. How do I fix it?

    Rented movies downloaded to an Apple TV can't be transferred to any other device.
    (86941)

  • I cannot see my wifi network but can see others

    i cannot see my wifi network but can see other networks
    anybody knows the soln

    Your wifi network is not working. Restart it. Delete your wifi settings for this network via System Preferences, Network, WiFi, Advanced. Reconfigure and try again.

  • I can see other accounts on home share and play the songs, but not drag them to my account.  Home share is on "on" on both accounts and both computers are authorized.  What can I do to copy the song from account to account?

    I can see other accounts on home share and play the songs, but not drag them to my account.  Home share is on "on" on both accounts and both computers are authorized.  What can I do to copy the song from account to account?

    okasy if you want to move the music from the other comptuer into your comptuer you can > but if they were purchased with a different APPLE id then you need to authorize the comptuer to play them .
    http://support.apple.com/kb/HT4527
    click homesharing > shows how to move the song onto your comptuer

  • Presonus Firebox problem: I can see the audio levels but can't hear. Help!

    Searched in the forums to what I think is a basic issue, but couldn't find anyone with an answer...
    I have audio routed into my firebox from an external mixer. I can see the audio meter in the "in" sound panel of system preferences moving but I can't hear sound coming out of my soundsticks.
    Audio routed out of my computer into external amp/stereo setup is audible, however.
    Can anyone help me figure this out so I can move and and start setting Firebox up with Logic? LOL
    My hardware specs (I'm running 10.4.11):
    Hardware Overview:
    Machine Name: Power Mac G4
    Machine Model: PowerMac3,5
    CPU Type: PowerPC G4 (2.1)
    Number Of CPUs: 2
    CPU Speed: 800 MHz
    L2 Cache (per CPU): 256 KB
    L3 Cache (per CPU): 2 MB
    Memory: 1.5 GB
    Bus Speed: 133 MHz
    Boot ROM Version: 4.2.5f1
    Serial Number:
    Sales Order Number:

    Your memory serves you well.
    Yes, line outs from the mixer are hooked up to line ins 3&4 on the back of the firebox. What I can't figure out is that the Sound Panel of System Preferences shows a good input level, whereas the meter in Logic shows nothing (rec is enabled and blinking). If I switch cables to the 1&2 instrument ins on the front of the Firebox, I get levels in both Sys Prefs and Logic. I'm thinking, the problem can't be the Firebox, because the computer sees the signal either way. I'm running Logic 6.0 Platinum BTW.
    I find Presonus and their manual to be lacking. They take days to write back with curt responses... Either they don't have enough people or the Firebox is not expensive enough for them to devote to customer service... I don't know

  • Convergence problem -- users seeing other users' mailboxes

    Hello, all!
    We seem to be having rather a shocking problem with Convergence -- in certain rare circumstances, people logging in to Convergence sometimes end up with other people's mailboxes instead of their own.
    Today, we had another of such incidents reported to our helpdesk -- after the issue was passed to my division, I decided to visit the affected user's desktop to see who they were logged in as, plus some particulars from cookes that Convergence uses, thinking that it may be related to a recent patch we received as a response from a Sun Support ticket filed about a similar incident. Afterwards, I went back to the server and started reading logs to see if I could pinpoint the root cause of what happened.
    Note that these logs have been sanitized -- <INCORRECT_USER> represents the username of the mailbox that the affected user saw instead of their own, <AFFECTED_IP> represents the IP address of the affected user's IP address, and <PREVIOUS_IP> represents the IP address of the user trying to access their mailbox that was seen by the affected user as well. (The IPs are not the same and are not in the same subnet.)
    So, from our Glassfish domain's access logs:
    "<AFFECTED_IP>" "NULL-AUTH-USER" "09/Nov/2010:11:04:37 -0600" "GET /iwc/svc/wmap/msg.mjs?rev=3&sid=&mbox=INBOX&uid=457&process=html%2Cjs%2Clink%2Ctarget%2Cbinhex&maxtext=155000&security=false&lang=en&token=KZc9jnOair&dojo.preventCache=1289322277283 HTTP/1.1" 200 6184
    That was the last access from the affected user's IP address before the incident begins -- this is just to show that they didn't log out. Then:
    "<PREVIOUS_IP>" "NULL-AUTH-USER" "09/Nov/2010:11:19:06 -0600" "GET /iwc_static/layout/login.html?lang=en-us&14.01_234924&svcs=abs,im,mail,calendar,c11n HTTP/1.1" 200 5095
    ...the other user visits the login page to try and log in. (I'll spare everyone the accesses to the preloading of Convergence's UI images. =) After a while, the other user attempts to log in and is successfully sent to main.html:
    "<PREVIOUS_IP>" "NULL-AUTH-USER" "09/Nov/2010:11:19:11 -0600" "POST /iwc/svc/iwcp/login.iwc HTTP/1.1" 200 312
    "<PREVIOUS_IP>" "NULL-AUTH-USER" "09/Nov/2010:11:19:11 -0600" "GET /iwc_static/layout/main.html?lang=en&14.01_234924& HTTP/1.1" 200 8856
    However, out of the blue:
    "<AFFECTED_IP>" "NULL-AUTH-USER" "09/Nov/2010:11:19:11 -0600" "POST /iwc/svc/iwcp/login.iwc HTTP/1.1" 200 312
    "<AFFECTED_IP>" "NULL-AUTH-USER" "09/Nov/2010:11:19:11 -0600" "POST /iwc/svc/wmap/cmd.mjs HTTP/1.1" 200 17
    ...the affected user tries to log in as well, then ask the AJAX cmd process to do something. The affected user mentioned that they usually stay connected to Convergence and just reopen a browser window when they need to check their mail. This seems consistent -- main.html probably prompted the affected user to retype their password to continue on after the previous commmand above failed after an expired session after they closed their browser window.
    Now, according to Convergence's iwc.log:
    AUTH: DEBUG from com.sun.comms.client.web.sso.SSOFilter Thread httpSSLWorkerThread-443-36 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:06,582- SSO is disabled
    AUTH: DEBUG from com.sun.comms.client.web.auth.IwcAuthController Thread httpSSLWorkerThread-443-36 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:06,583- No valid session found, redirecting to login page
    AUTH: DEBUG from com.sun.comms.client.web.auth.IwcAuthController Thread httpSSLWorkerThread-443-36 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:06,584- Redirecting to: /iwc_static/layout/login.html?lang=en-us&14.01_234924&svcs=abs,im,mail,calendar,c11n
    The other user visits the site and is redirected to login.html, then...
    AUTH: DEBUG from com.sun.comms.client.web.sso.SSOFilter Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,410- SSO is disabled
    PROTOCOL: DEBUG from com.sun.comms.client.protocol.ProtocolEngineServlet Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,411- Iwc Protocol command issued: login.iwc
    AUTH: WARN from com.sun.comms.client.protocol.delegate.agent.LoginContextAgent Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,413- Subject not found in session, creating one
    AUTH: DEBUG from com.sun.comms.client.protocol.delegate.agent.LoginContextAgent Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,414- Loaded com.sun.comms.client.security.auth.AppCallbackHandler class
    AUTH: DEBUG from com.sun.comms.client.security.auth.modules.impl.SunLDAPLoginModule Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,416- SunLDAPLoginModule:initialize()
    AUTH: DEBUG from com.sun.comms.client.security.auth.modules.impl.SunLDAPLoginModule Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,504- SunLDAPLoginModule:login()
    AUTH: INFO from com.sun.comms.client.security.auth.modules.impl.SunAuthCallBack Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,506- User LoginID is <INCORRECT_USER>
    AUTH: DEBUG from com.sun.comms.client.security.auth.modules.impl.SunAuthCallBack Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,508- Host header is connect.siue.edu
    AUTH: DEBUG from com.sun.comms.client.security.auth.modules.impl.SunAuthCallBack Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,510- Attempting to resolve User's domain/organization: siue.edu from the host header...
    AUTH: INFO from com.sun.comms.client.security.auth.modules.impl.SunAuthCallBack Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,511- User domain is siue.edu
    AUTH: DEBUG from com.sun.comms.client.security.auth.AppCallbackHandler Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,513- Done Handling Callback class: com.sun.comms.client.security.auth.modules.impl.SunLDAPAuthCallBack
    AUTH: DEBUG from com.sun.comms.client.security.auth.AppCallbackHandler Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,514- Done Handling Callback class: com.sun.comms.client.security.auth.AuthorizationIdCallback
    AUTH: DEBUG from com.sun.comms.client.security.auth.modules.impl.SunLDAPLoginModule Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,516- SunLDAPLoginModule:lookupUser()
    AUTH: INFO from com.sun.comms.client.security.auth.modules.impl.SunLDAPLoginModule Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,517- Loaded UG LDAP pool...
    AUTH: DEBUG from com.sun.comms.client.security.auth.modules.impl.SunLDAPLoginModule Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,521- Releasing UG LDAP to pool
    AUTH: DEBUG from com.sun.comms.client.security.auth.modules.impl.SunLDAPLoginModule Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,523- Loaded Auth LDAP pool...
    AUTH: DEBUG from com.sun.comms.client.security.auth.modules.impl.SunLDAPLoginModule Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,527- Releasing Auth LDAP to pool
    AUTH: INFO from com.sun.comms.client.security.auth.modules.impl.SunLDAPLoginModule Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,529- SunLDAPLoginModule:User <INCORRECT_USER> Authenticated
    AUTH: INFO from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,533- Loading user entry from LDAP
    ...the other user successfully logs in (using an external Sun-based LDAP server), then starts asking the LDAP server for their Convergence preferences.
    AUTH: DEBUG from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,535- Creating Comms User.....
    AUTH: DEBUG from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,537- Creating new User
    (That's interesting...)
    AUTH: DEBUG from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,539- Login id of the user is <INCORRECT_USER>
    AUTH: DEBUG from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,541- Domain name of the user is siue.edu
    AUTH: DEBUG from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,544- Org DN of the user is o=siue.edu,o=usergroup
    AUTH: DEBUG from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,546- Real domain name of the user is siue.edu
    AUTH: INFO from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,548- User entry loaded successfully
    AUTH: DEBUG from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,550- Updating user cache with default attribute values
    AUTH: DEBUG from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,552- Updating user cache common preference with default values
    AUTH: DEBUG from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,555- Processing AttrName: sunUCDefaultApplication
    AUTH: DEBUG from com.sun.comms.client.security.auth.CommsUserInitContext Thread httpSSLWorkerThread-443-33 ipaddress=<PREVIOUS_IP> sessionid= at 11/09/10 11:19:14,557- Preference Attribute : sunUCDefaultApplication is not present in user cache
    And intermixed with the loading of preferences for the other user...
    AUTH: DEBUG from com.sun.comms.client.web.sso.SSOFilter Thread httpSSLWorkerThread-443-18 ipaddress=<AFFECTED_IP> sessionid= at 11/09/10 11:19:14,666- SSO is disabled
    PROTOCOL: DEBUG from com.sun.comms.client.protocol.ProtocolEngineServlet Thread httpSSLWorkerThread-443-18 ipaddress=<AFFECTED_IP> sessionid= at 11/09/10 11:19:14,667- Iwc Protocol command issued: login.iwc
    AUTH: WARN from com.sun.comms.client.protocol.delegate.agent.LoginContextAgent Thread httpSSLWorkerThread-443-18 ipaddress=<AFFECTED_IP> sessionid= at 11/09/10 11:19:14,669- Subject not found in session, creating one
    AUTH: DEBUG from com.sun.comms.client.protocol.delegate.agent.LoginContextAgent Thread httpSSLWorkerThread-443-18 ipaddress=<AFFECTED_IP> sessionid= at 11/09/10 11:19:14,671- Loaded com.sun.comms.client.security.auth.AppCallbackHandler class
    AUTH: DEBUG from com.sun.comms.client.security.auth.modules.impl.SunLDAPLoginModule Thread httpSSLWorkerThread-443-18 ipaddress=<AFFECTED_IP> sessionid= at 11/09/10 11:19:14,674- SunLDAPLoginModule:initialize()
    AUTH: DEBUG from com.sun.comms.client.security.auth.modules.impl.SunLDAPLoginModule Thread httpSSLWorkerThread-443-18 ipaddress=<AFFECTED_IP> sessionid= at 11/09/10 11:19:14,676- SunLDAPLoginModule:login()
    AUTH: INFO from com.sun.comms.client.security.auth.modules.impl.SunAuthCallBack Thread httpSSLWorkerThread-443-18 ipaddress=<AFFECTED_IP> sessionid= at 11/09/10 11:19:14,678- User LoginID is <INCORRECT_USER>
    ...there's the affected user trying to log in -- and getting the same username as the other user!
    AUTH: DEBUG from com.sun.comms.client.web.sso.SSOFilter Thread httpSSLWorkerThread-443-32 ipaddress=<AFFECTED_IP> sessionid=0fabb5152fbab756c5ef6cdb2c1d at 11/09/10 11:19:14,933- SSO is disabled
    AUTH: DEBUG from com.sun.comms.client.web.authorization.MailAuthorizationFilter Thread httpSSLWorkerThread-443-32 ipaddress=<AFFECTED_IP> sessionid=0fabb5152fbab756c5ef6cdb2c1d at 11/09/10 11:19:14,935- Removing token parameter from the mail backend service request
    PROXY_MAIL: DEBUG from com.sun.comms.client.web.services.sun.MailServiceProxy Thread httpSSLWorkerThread-443-32 ipaddress=<AFFECTED_IP> sessionid=0fabb5152fbab756c5ef6cdb2c1d at 11/09/10 11:19:14,938- reqURI: /iwc/svc/wmap/cmd.mjs
    The affected user (seeing that they have less to load) tries to send the command referenced above. Note their session ID...
    AUTH: DEBUG from com.sun.comms.client.web.sso.SSOFilter Thread httpSSLWorkerThread-443-37 ipaddress=<PREVIOUS_IP> sessionid=1a60d56c1deb585e05bf126aa4fe at 11/09/10 11:19:15,740- SSO is disabled
    PROTOCOL: DEBUG from com.sun.comms.client.protocol.ProtocolEngineServlet Thread httpSSLWorkerThread-443-37 ipaddress=<PREVIOUS_IP> sessionid=1a60d56c1deb585e05bf126aa4fe at 11/09/10 11:19:15,831- Iwc Protocol command issued: get_allprefs.iwc
    PROTOCOL: WARN from com.sun.comms.client.protocol.delegate.UserPrefsCommandDelegate Thread httpSSLWorkerThread-443-37 ipaddress=<PREVIOUS_IP> sessionid=1a60d56c1deb585e05bf126aa4fe at 11/09/10 11:19:15,834- get_allprefs.iwc : Service is not enabled : smime
    CONFIG: DEBUG from com.sun.comms.client.web.ServerConfiguration Thread httpSSLWorkerThread-443-37 ipaddress=<PREVIOUS_IP> sessionid=1a60d56c1deb585e05bf126aa4fe at 11/09/10 11:19:15,837- Virtual domain is enabled
    PROTOCOL: WARN from com.sun.comms.client.protocol.delegate.agent.ClientOptionsAgent Thread httpSSLWorkerThread-443-37 ipaddress=<PREVIOUS_IP> sessionid=1a60d56c1deb585e05bf126aa4fe at 11/09/10 11:19:15,839- client preferences not found for domain: siue.edu
    ...and how it's completely different from the other user's session ID. (One odd note -- the other user's browser asks for get_allprefs.iwc, but the affected user's browser doesn't until much later when, after seeing the incorrect mailbox, tried to rectify the problem by closing their browser and revisiting the domain, which bounced them off to main.html since they (apparently) had a valid session:
    From Glassfish's access logs:
    "<AFFECTED_IP>" "NULL-AUTH-USER" "09/Nov/2010:11:24:48 -0600" "GET / HTTP/1.1" 200 279
    "<AFFECTED_IP>" "NULL-AUTH-USER" "09/Nov/2010:11:24:48 -0600" "GET /iwc/ HTTP/1.1" 302 0
    "<AFFECTED_IP>" "NULL-AUTH-USER" "09/Nov/2010:11:24:48 -0600" "GET /iwc_static/layout/main.html?lang=en-us&14.01_234924 HTTP/1.1" 200 8856
    And from Convergence's iwc.log:
    AUTH: DEBUG from com.sun.comms.client.web.sso.SSOFilter Thread httpSSLWorkerThread-443-36 ipaddress=<AFFECTED_IP> sessionid=1a60de74f3d0ef2780bc181221e2 at 11/09/10 11:24:50,928- SSO is disabled
    AUTH: DEBUG from com.sun.comms.client.web.auth.IwcAuthController Thread httpSSLWorkerThread-443-36 ipaddress=<AFFECTED_IP> sessionid=1a60de74f3d0ef2780bc181221e2 at 11/09/10 11:24:50,934- Found a valid session, redirecting user to the main view page
    PROTOCOL: WARN from com.sun.comms.client.protocol.delegate.agent.ClientOptionsAgent Thread httpSSLWorkerThread-443-36 ipaddress=<AFFECTED_IP> sessionid=1a60de74f3d0ef2780bc181221e2 at 11/09/10 11:24:50,952- client preferences not found for domain: siue.edu
    AUTH: DEBUG from com.sun.comms.client.web.sso.SSOFilter Thread httpSSLWorkerThread-443-37 ipaddress=<AFFECTED_IP> sessionid=1a60de74f3d0ef2780bc181221e2 at 11/09/10 11:24:51,947- SSO is disabled
    PROTOCOL: DEBUG from com.sun.comms.client.protocol.ProtocolEngineServlet Thread httpSSLWorkerThread-443-37 ipaddress=<AFFECTED_IP> sessionid=1a60de74f3d0ef2780bc181221e2 at 11/09/10 11:24:51,949- Iwc Protocol command issued: get_allprefs.iwc
    PROTOCOL: WARN from com.sun.comms.client.protocol.delegate.UserPrefsCommandDelegate Thread httpSSLWorkerThread-443-37 ipaddress=<AFFECTED_IP> sessionid=1a60de74f3d0ef2780bc181221e2 at 11/09/10 11:24:51,951- get_allprefs.iwc : Service is not enabled : smime
    CONFIG: DEBUG from com.sun.comms.client.web.ServerConfiguration Thread httpSSLWorkerThread-443-37 ipaddress=<AFFECTED_IP> sessionid=1a60de74f3d0ef2780bc181221e2 at 11/09/10 11:24:51,952- Virtual domain is enabled
    PROTOCOL: WARN from com.sun.comms.client.protocol.delegate.agent.ClientOptionsAgent Thread httpSSLWorkerThread-443-37 ipaddress=<AFFECTED_IP> sessionid=1a60de74f3d0ef2780bc181221e2 at 11/09/10 11:24:51,954- client preferences not found for domain: siue.edu
    (Again, what's odd is that the JSESSIONID changes again.)
    I thought initially that it may be a pooling problem, so I decided to check out the logs for the Sun ONE Directory Server that this instance of Convergence is connected to and:
    [09/Nov/2010:11:19:14 -0600] conn=407075 op=22106 msgId=86900 - SRCH base="o=siue.edu,o=usergroup" scope=2 filter="(uid=<INCORRECT_USER>)" attrs="* isMemberOf"
    [09/Nov/2010:11:19:14 -0600] conn=407075 op=22106 msgId=86900 - RESULT err=0 tag=101 nentries=1 etime=0
    [09/Nov/2010:11:19:14 -0600] conn=408714 op=2173 msgId=86901 - BIND dn="uid=<INCORRECT_USER>,ou=People,o=siue.edu,o=usergroup" method=128 version=3
    [09/Nov/2010:11:19:14 -0600] conn=408714 op=2173 msgId=86901 - RESULT err=0 tag=97 nentries=0 etime=0 dn="uid=<INCORRECT_USER>,ou=people,o=siue.edu,o=usergroup"
    [09/Nov/2010:11:19:14 -0600] conn=408784 op=4786 msgId=86902 - SRCH base="o=siue.edu,o=usergroup" scope=2 filter="(uid=<INCORRECT_USER>)" attrs="* isMemberOf"
    [09/Nov/2010:11:19:14 -0600] conn=408784 op=4786 msgId=86902 - RESULT err=0 tag=101 nentries=1 etime=0
    [09/Nov/2010:11:19:14 -0600] conn=408714 op=2174 msgId=86903 - BIND dn="uid=<INCORRECT_USER>,ou=People,o=siue.edu,o=usergroup" method=128 version=3
    [09/Nov/2010:11:19:14 -0600] conn=408714 op=2174 msgId=86903 - RESULT err=0 tag=97 nentries=0 etime=0 dn="uid=<INCORRECT_USER>,ou=people,o=siue.edu,o=usergroup"
    But two different LDAP connections.... well, actually four... searched for and bound to the other user's username.
    The other interesting thing I found was while I was searching for the other user's username in the LDAP logs -- earlier I pointed out an interesting entry about "creating a Comms user"; however, the other user logged in previously to Convergence:
    [08/Nov/2010:21:23:10 -0600] conn=407075 op=18839 msgId=75351 - SRCH base="o=siue.edu,o=usergroup" scope=2 filter="(uid=<INCORRECT_USER>)" attrs="* isMemberOf"
    [08/Nov/2010:21:23:10 -0600] conn=407075 op=18839 msgId=75351 - RESULT err=0 tag=101 nentries=1 etime=0
    [08/Nov/2010:21:23:10 -0600] conn=408714 op=680 msgId=75352 - BIND dn="uid=<INCORRECT_USER>,ou=People,o=siue.edu,o=usergroup" method=128 version=3
    [08/Nov/2010:21:23:10 -0600] conn=408714 op=680 msgId=75352 - RESULT err=0 tag=97 nentries=0 etime=0 dn="uid=<INCORRECT_USER>,ou=people,o=siue.edu,o=usergroup"
    I'm stumped -- anyone have any ideas why this is happening to us? (Due to these problems, we've been forced to shutdown our Convergence servers and redirect users to another older webmail product until this is fixed.)

    >
    The other interesting thing I found was while I was searching for the other user's username in the LDAP logs -- earlier I pointed out an interesting entry about "creating a Comms user"; however, the other user logged in previously to Convergence:"creating a Comms user" => means creating user object in memory using details in the LDAP and configuration, it does not create a User entry in LDAP.
    Can you please provide following details:
    - version of Convergence
    - output of 'iwcadmin -l'
    - full iwc.log and glassfish access log file

  • Isight problem like thousand of other users !!!

    I don't believe it but I am having the same problem like many other users. I am getting my masters in computer science next year and I know how to handle a computer, just to make this clear.
    What makes me really mad is that many other users are struggling with the same problem as I do, but there is no help coming from apple, as it seems to be.
    So anyway, my problem is that my webcam on my macbook pro works for a few minuits or sometimes for a few seconds, then I have this **** black screen, but the led is green.
    If I do the pmu or whatever it is called, the camera works sometimes again, but as I have written, sometimes for a few minuits/ seconds, then it stops .
    Since I searched the web or this forum here, there are so many guys complaining about the same problem, but seriously, did everybody go to the service ?
    I just bought my notebook three months ago, but this problem seems to be familiar for at least two or three years now. This problem should have been fixed by now. !
    Any suggestion ? Maybe someone solved the problem and would like to share his idea :)?

    Apologies, I don't have the issue (but I do have a Masters degree in computational science) - does the screen go black, or just very, very, very dark, ie. if you turn all the lights on, do you get anything one the screen.
    Trying to establish if the exposure metering is wrong, or if it's a physical issue with the camera (in which case you can have this fixed under AppleCare).
    Which applications are you using when the isight loses it ?
    Are you using any of the quartz effects ?

  • I want to secure my email account for other users of the i-pad. Is this possible?

    I want to secure my e-mail account for other users of the i-pad....
    Is this possible???

    no.
    The only way is if you use a webmail app - not the included e-mail app - so you can password protect it online.
    The iPad is meant to be a single user device so it has no protocols to partition off any part of it (beyond what restrictions allow)

  • I can see other Macs on network, but I can't connect via afp, smb or Bonjour

    Hello.
    I have a Mac Pro running 10.6.8, a Macbook Pro running Lion, an Ipad 2nd generation and an Iphone 4. All the devices "see" each other, but I am unable to establish a connection.
    For instance: I can see the other mac in the finder, but a connection can't be made neither via clicking or using command + K
    I can see my iTunes libraries in the remote app, but it wont connect to the iTunes library. Same with iChat: in the Bonjour network both macs see each other, but no message is delivered.
    However, I can connect to the harddrive, that is connected to my airport extreme. Previously I thought my router was the problem, but now I exchanged it with this airport Extreme.
    In another thread I read something about adding 10.0.1.* to "Bypass proxy settings for these Hosts and Domains" in the network proxy settings, but this did not help. Although I am not sure if I entered it right.
    Any ideas how to resolve this problem?

    Hi,
    Please turn off the Windows Firewall in the Control Panel for test:
    Control Panel->type firewall in the search box->Windows Firewall->Turn Windows Firewall on or off->Turn off
    Windows Firewall (not recommended)->OK
    Then Make sure all computer
    turn on the network discovery. 
    Also, apps that are managed from non-domain servers cannot see or control this Windows 7 machine
    In addition, make sure the Server, Windows 7 and other comouter in the same network. Otherwise it can't be accessed each other.
    Karen Hu
    TechNet Community Support

  • With VPD I see other users results - problems with AM caching??

    I am using JDeveloper 11.1.1.0.2.
    In my application I have 3 Appllication Modules (Admin, Store and Sale) and I use VPD and setcontext in every AM.
    @Override
    protected void prepareSession(Session session) {
    super.prepareSession(session);
    setVPDcontext();
    private void setVPDcontext() {
    String userName = getUserContext().getUserId();
    String ind = "J";
    String sql =
    "begin xxx_context.set_context('" + userName +
    "', '" + ind + "'); end;";
    java.sql.CallableStatement stmt = null;
    try {
    stmt = getDBTransaction().createCallableStatement(sql, 0);
    stmt.execute();
    catch (SQLException se) {
    throw new JboException(se.getMessage());
    finally {
    if (stmt != null) {
    try {
    stmt.close();
    catch (SQLException e) {
    throw new JboException(e);
    The problem is that I see the results of previous VPD-queries.
    3 testcases:
    1. User1 has access to 3 AM (Admin, Store, Sale), if I log in I can see the correct results in the application (in Admin, Store and Sale).
    User2 has only access to 1 AM (Store), If I log in as User2 I see the results of User1 in Store (wrong).
    2. After restarting the weblogic server and logging in as User2 I see the correct results for User2!
    If I log in as User1 I see the results of User2 in Store (wrong!!) and the correct results in Admin and Sale!
    3. User1 has access to 3 AM (Admin, Store, Sale), if I login as user User1 I only use Admin and Sale (so there are no cached results for Store).
    User3 has access to Sale and Store. If I login as User3 I see the results of User1 in Sale and the correct result in Store.
    Conclusion: I see cached query results of the first user who logges in a Application Module. Only restarting the Weblogic Server makes the cache empty. The problem only occurs with queries with VPD.
    How can I resolve this problem?

    User,
    I'm on a bind variable crusade today (not the answer to your question, unfortunately). Please please please please use bind variables instead of gluing literals together like that (use PreparedStatement instead of callable statement). You can also parse the PreparedStatement once and avoid the overhead of parsing on each call to prepareSession.
    John

Maybe you are looking for

  • Java.lang.NullPointerException in session bean

    Hi ! I am trying to get a Entity bean through "LocalHome.findByPrimaryKey".I get an error:java.lang.NullPointerException. this is session bean: public class LoginBean implements javax.ejb.SessionBean { private javax.ejb.SessionContext mySessionCtx; p

  • Javascript in pl/sql process block

    Hi, Can someone please tell me why this code is not working..... I have put this in my pl/sql process.... htp.p('<script language=javascript>'); htp.p('var r=confirm("This is a duplicate record , do you want to proceed?");'); htp.p('if (r==true)'); h

  • Play a specific part of a timeline

    I found this topic which is really close: Play a specific part of a timeline I have 4 objects sitting in a circle. Similar to a compass. When I click on one of the objects, it should move in a circular path to the topmost position (north). It can go

  • Error in installing OID PatchSet (OID9022) - Urgent..

    Currently, i try to install the OID9022 patchset in infrastructure instance. So, i try to run patch.sh %./patch.sh SHUTDOWN ALL THE OID Processes SHUTDOWN THE LISTENER *** Important *** This patch should be installed on OID 9.0.2.1.0 only Do you want

  • Error when executing sql-statement

    I get the following error: select commodity_id from book where CONTAINS(review,'%a%')>0; ORA-29902: error in executing ODCIIndexStart() routine ORA-20000: interMedia Text error: DRG-50937: query too complex DRG-51030: wildcard query expansion resulte