07-16-04 10:50 PM
Each resource (Catalogs, Campaigns) have and understand only their
authorization policy structures. An authorization policy has an application
which contains the operations and tasks in it. When accessing the
authorization policy the Application name has to be specified. Since you
are creating your own authorization ploicy for your custom resource the
Agent API cannot use it to perform authorizations since it does not
understand/interpret its contents.
In your post if you are talking about creating an authorization policy for
the catalog resource then yes the Agent API will check against it.
Bottomline is if you create your own custom resource and an authorization
policy for that resource then you will have to write your own authorization
logic.
--------------------
Content-Class: urn:content-classes:message
From: "Ravi Shankar" <shankar.nospam@hp.com>
Sender: "Ravi Shankar" <shankar.nospam@hp.com>
References: <2c92c01c4698f$c00a3230$a501280a@phx.gbl>
<w0NDIycaEHA.2804@cpmsftngxa06.phx.gbl>
<2d2a501c46a26$4dd80240$a401280a@phx.gbl>
<WhqwyfpaEHA.2752@cpmsftngxa06.phx.gbl>
Subject: RE: Exposing Custom Resources as Web Services for FP1 style FE apps
Date: Thu, 15 Jul 2004 21:44:48 -0700
Lines: 146
Message-ID: <2e7ad01c46aef$9fe74b80$a301280a@phx.gbl>
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Newsreader: Microsoft CDO for Windows 2000
Thread-Index: AcRq75/n+VvAKAYQQpC3Cpnv20PtNg==
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4910.0300
Newsgroups: microsoft.public.commerceserver.general
Path: cpmsftngxa06.phx.gbl
Xref: cpmsftngxa06.phx.gbl microsoft.public.commerceserver.general:14271
NNTP-Posting-Host: tk2msftngxa11.phx.gbl 10.40.1.163
X-Tomcat-NG: microsoft.public.commerceserver.general
The policy would contain all that since I created it
using the "Authorization Manager" in Developer mode
So the Agent API would check up OK against it, right ?
Regards.
>-----Original Message-----
>If this policy is for your custom application/resource
then the commerce
>server APIs will not understand and use it. You will
have to write your own
>authorization code to authorize users using your custom
policy.
>Basically the authorization policy consists of an
application, operations
>and tasks and there are APIs to perform access checks
against the
>authorization policy.
>
>--------------------
>Content-Class: urn:content-classes:message
>From: "Ravi Shankar" <shankar.nospam@hp.com>
>Sender: "Ravi Shankar" <shankar.nospam@hp.com>
>References: <2c92c01c4698f$c00a3230$a501280a@phx.gbl>
><w0NDIycaEHA.2804@cpmsftngxa06.phx.gbl>
>Subject: RE: Exposing Custom Resources as Web Services
for FP1 style FE apps
>Date: Wed, 14 Jul 2004 21:43:42 -0700
>Lines: 83
>Message-ID: <2d2a501c46a26$4dd80240$a401280a@phx.gbl>
>MIME-Version: 1.0
>Content-Type: text/plain;
> charset="iso-8859-1"
>Content-Transfer-Encoding: quoted-printable
>X-Newsreader: Microsoft CDO for Windows 2000
>X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4910.0300
>Thread-Index: AcRqJk3VqQDYFCIkQqa7Demtuxz13w==
>Newsgroups: microsoft.public.commerceserver.general
>Path: cpmsftngxa06.phx.gbl
>Xref: cpmsftngxa06.phx.gbl
microsoft.public.commerceserver.general:14255
>NNTP-Posting-Host: tk2msftngxa12.phx.gbl 10.40.1.164
>X-Tomcat-NG: microsoft.public.commerceserver.general
>
>I'll try that and get back..
>Second question --
>I can create an authroization policy for the application
>as part of this and get the web service to use that.
>Would the Agent API exposed on the FE support my policy
>files ? or Would something else need to be done for it ?
>Thanks and Regards.
>the sitename from
>the information
pass[vbcol=seagreen]
>in the web service
>FP1 style FE apps
>microsoft.public.commerceserver.general:14250
>providing
>custom
site[vbcol=seagreen]
>IHTTPConfigurationHandler ?
and[vbcol=seagreen]
>confers no rights.
>Corporation. All rights
>specified at
>http://www.microsoft.com/security. Please
>
>
>Thanks
>Vinayak Tadas
>Microsoft
>http://blogs.msdn.com/vinayakt
>
>This posting is provided "AS IS" with no warranties, and
confers no rights.
>You assume all risk for your use. © 2002 Microsoft
Corporation. All rights
>reserved.
>Use of included script samples are subject to the terms
specified at
>http://www.microsoft.com/info/cpyright.htm
>Get Secure! For more info visit
http://www.microsoft.com/security. Please
>reply to the newsgroups only. Thanks
>
Thanks
Vinayak Tadas
Microsoft
http://blogs.msdn.com/vinayakt
This posting is provided "AS IS" with no warranties, and confers no rights.
You assume all risk for your use. © 2002 Microsoft Corporation. All rights
reserved.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm
Get Secure! For more info visit http://www.microsoft.com/security. Please
reply to the newsgroups only. Thanks
[ Post a follow-up to this message ]
|