[mapguide][MG446][New] DWF Viewer security

Andrew andrew.demerchant at gemtec.ca
Tue Nov 7 22:42:25 EST 2006


You can view the artifact detail at the following URL:

    https://mapguide.osgeo.org/servlets/Scarab/id/MG446

Type
 Defect

Artifact ID
 MG446 (DWF Viewer security)

Reported by
 Andrew
 andrew_demerchant (andrew.demerchant at gemtec.ca)

New artifact details:
---------------------------------------------------------

- Component set to new value
  Viewer
- Version set to new value
  1.0.2
- Steps to Reproduce set to new value
  Remove the "everyone" group for a library. Add a new user, and then add that to your library. Then try to use the dwf viewer for that library. You will not be prompted to login. Instead you will see an error:


Permission denied to resource: Library://test/

Permission denied to resource: Library://test/ Exception occurred in method MgResourceHeaderManager.CheckPermission at line 2495 in file c:\build_tux_area\mgdev_opensource\server\src\services\resource\ResourceHeaderManager.cpp 


If you simply change the URL to use the ajax viewer, the login prompt is displayed, and all works as you'd expect. 
- Defect Severity set to new value
  Critical
- Artifact Status set to new value
  New
- Artifact created
- Operating system set to new value
  Windows 2000
- Platform set to new value
  PC
- Subcomponent set to new value
  DWF Viewer
- Summary set to new value
  DWF Viewer security
- Description set to new value
  Can't secure a library using the DWF viewer. If you try to remove the "everyone" user and force the user to log in, you 'll get:

Permission denied to resource: Library://test/

Permission denied to resource: Library://test/ Exception occurred in method MgResourceHeaderManager.CheckPermission at line 2495 in file c:\build_tux_area\mgdev_opensource\server\src\services\resource\ResourceHeaderManager.cpp 

This works fine in the ajax viewer though. The DWF viewer simply doesn't let the user have a chance to log in.

---------------------------------------------------------
This message was automatically generated by Project Tracker.








More information about the Mapguide_issues mailing list