View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0009429 | Compliance Test Tool (CTT) Unified Architecture | 5 - General Problem | public | 2024-02-21 10:47 | 2024-09-20 11:30 |
Reporter | Thomas Merk | Assigned To | Paul Hunkar | ||
Priority | normal | Severity | minor | Reproducibility | always |
Status | feedback | Resolution | open | ||
Product Version | 1.04.11-01.00.506 | ||||
Summary | 0009429: Security - User - Anonymous - 002.js | ||||
Description | Script expects service result BadIdentityTokenRejected The UserIdentityToken contains a poilcy ID which is not exposed by server e.g. "Anonymous_Channel" but the server exposes "Anonymous". In general it is not clearly stated in part 4 - ActivateSession in which cases the service results shall be used
At least our server returns
All service results are accepted by CTT - except the last one (as far as I know issued token are not tested). | ||||
Tags | No tags attached. | ||||
Files Affected | |||||
|
Sorry, I misunderstood the results (and mixed output with 003). The test case excpects that activate session succeeds, but CTT uses wrong policyId for Anonymous user identity - no idea why. |
|
We think this was fixed in 508 - can you please check? |
Date Modified | Username | Field | Change |
---|---|---|---|
2024-02-21 10:47 | Thomas Merk | New Issue | |
2024-02-21 15:31 | Thomas Merk | Note Added: 0020850 | |
2024-09-20 11:30 | Paul Hunkar | Assigned To | => Paul Hunkar |
2024-09-20 11:30 | Paul Hunkar | Status | new => feedback |
2024-09-20 11:30 | Paul Hunkar | Note Added: 0021757 |