Focal Point
[CASE-OPENED] Resource Management - 403 - Forbidden: Access is denied.

This topic can be found at:
https://forums.informationbuilders.com/eve/forums/a/tpc/f/7971057331/m/3217075676

June 05, 2015, 01:57 PM
Yazster
[CASE-OPENED] Resource Management - 403 - Forbidden: Access is denied.
Hi All,

I recently upgraded our development environment to WF 8.104. We've encountered a few hiccups along the way, this being one of them.
When I access the reporting server from WebFocus (Trusted Connection), and run Resource Management reports, all reports work. Problem is, whenever I click on one of the available hyperlinks/drilldowns in these reports, I get a 403 - Forbidden: Access is denied. error.

If I login directly to the reporting server (Explicit Connection), everything works fine.

I'm using LDAP as my primary security provider, and other than the Resource Management reports, all seems to be working fine.

Any thoughts? Confused

This message has been edited. Last edited by: <Kathryn Henning>,


WebFOCUS 8.201M
Windows, Linux, All Outputs
June 05, 2015, 03:07 PM
eric.woerle
I would compare what groups you are registered as when connecting through a trusted connection versus an explicit connection. In WF8008, when logging in explicitly, my groups are based on my LDAP groups. When logging in through a Trusted Connection, my groups are based on the groups from the Client. Depending on how your rules are setup, this might have an impact...


Eric Woerle
8.1.05M Gen 913- Reporting Server Unix
8.1.05 Client Unix
Oracle 11.2.0.2
June 05, 2015, 03:58 PM
Yazster
Thanks Eric,

You're absolutely correct, when I login explicitly I see my LDAP groups vs WF groups with the trusted connection.

With 8008 though (our production environment), this works fine. Our upgraded dev environment doesn't. I've opened a couple of cases recently regarding ldap configuration issues with the update, perhaps this was affected as well...

Not quite sure what changed or what needs to be done on my side to enable this functionality.


WebFOCUS 8.201M
Windows, Linux, All Outputs
June 05, 2015, 04:02 PM
eric.woerle
Don't know either. I just thought I would mention that in case your adminstrator abilities are set by the recognized group. To that extent maybe the intitial request is using the LDAP group, where the drill passing back through the RS is recognizing the Group as it passed by the Web Client. Or maybe the reverse...


Eric Woerle
8.1.05M Gen 913- Reporting Server Unix
8.1.05 Client Unix
Oracle 11.2.0.2
June 11, 2015, 03:20 PM
Yazster
Last update from the case I opened regarding this issue:

quote:
this is a known issue with the WebFOCUS 810x
client and has been fixed in the WebFOCUS 820x client that will be available
later this year.


FYI


WebFOCUS 8.201M
Windows, Linux, All Outputs