Uploaded image for project: 'JBoss BPMS Platform'
  1. JBoss BPMS Platform
  2. RHBPMS-1904

Restrict insecure Remote task operations (not only limited to GetTask* commands)

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • 6.4.0
    • 6.2.0
    • Business Central
    • None

    Description

      Description of problem:

      I am trying to with below API's to list the HumanTask assigned to group through Remote REST API's but it fails with exception:

      ~~~
      Unable to execute GetTaskAssignedAsPotentialOwnerCommand/0: org.kie.remote.services.rest.exception.KieRemoteRestOperationException: Organizational entity already exists with [UserImpl:'HR'] id, please check that there is no group and user with same id
      ~~~

      Code:
      =====================
      RuntimeEngine engine = RemoteRuntimeEngineFactory.newRestBuilder()
      .addUrl(url).addUserName(userName).addPassword(passWord)
      .addDeploymentId(deploymentId).build();

      KieSession ksession = engine.getKieSession();
      TaskService taskService = engine.getTaskService();

      ProcessInstance processInstance = ksession.startProcess("project1.TestProcess");
      tasklist = taskService.getTasksAssignedAsPotentialOwner("HR","en-UK");

      =====================

      Version-Release number of selected component (if applicable):
      BPMS 6.2.2

      How reproducible:

      Steps to Reproduce:
      1. Start server(BPMS 6.2.2) with -Dorg.kie.task.insecure=true and deploy attached kajr.
      2. Apply one-off patch attached to BZ-1325945 and use -Dorg.kie.task.insecure=true option in client side and server side.
      3. Try to list task using Remote REST API

      Actual results:
      Not able to list User Task assigned to group through Remote REST API

      Expected results:
      User should be able to list task assigned to group through Remote REST API

      Additional info:

      Attachments

        Issue Links

          Activity

            People

              marco.rietveld Marco Rietveld (Inactive)
              rhn-support-abhumbe Abhijit Humbe
              Tomáš Livora Tomáš Livora (Inactive)
              Tomáš Livora Tomáš Livora (Inactive)
              William Siqueira
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: