tag:blogger.com,1999:blog-1816408742331555186.post6898623729258609922..comments2023-05-22T03:03:54.478-07:00Comments on Oracle Fusion Middleware Security: Developing Workflows to OIM 11g - the basicsChris Johnson (Oracle)http://www.blogger.com/profile/13331466366556759355noreply@blogger.comBlogger3125tag:blogger.com,1999:blog-1816408742331555186.post-14919256521334936932012-11-22T02:51:08.478-08:002012-11-22T02:51:08.478-08:00Awesome work... Awesome work... Chellappan Sampathhttps://www.blogger.com/profile/10947433091439152474noreply@blogger.comtag:blogger.com,1999:blog-1816408742331555186.post-81868974887267817482011-04-22T08:33:53.015-07:002011-04-22T08:33:53.015-07:00Good Work.Good Work.sivahttps://www.blogger.com/profile/07197467489515864074noreply@blogger.comtag:blogger.com,1999:blog-1816408742331555186.post-39484728490751505562011-04-21T10:12:53.544-07:002011-04-21T10:12:53.544-07:00Hello , I would like to request your help on a sec...Hello , I would like to request your help on a security issue<br />We have solution in which users from company A will need to access Worklist UI hosted in Company B. When users in company A access worklist UI, authentication will be done in company A with WebSEAL, and it will set userid and groups in the http header, then the request will be redirected to company B. Potential groups in http headers will be supplied to Company B through a manual process as a initial setup, and all the worklist roles will be based on these groups.<br /><br />Company B does not need to authenticate, it can assume/trust the incoming request is valid, and requested user will need to see the work! list task home page, Company B worklist should not ask user to login again.<br /><br />Complexity we have are, users from company A are not maintained or persevered in Company B, so the user id in http header will not be a valid worklist user. How could we create this users dynamically , assign it to pre-created groups, and login to worklist with that, all in one use case ?.<br /><br />Is there a way to login worklist directly without going login page ?. I tried following url extracted using tcpmon, but it is still going to login page,<br /><br />http://uspns162.elabs.eds.com:8001/integration/worklistapp/faces/login.jspx?_adf.ctrl-state=pcr1myli1_4&userNameField=weblogic&passwordField=welcome1&org.apache.myfaces.trinidad.faces.FORM=j_id__ctru5&javax.faces.ViewState=hwbx5dazt<br /><br /><br />I appreciate your help and welcome all suggestions and commentsNaheed MKhttps://www.blogger.com/profile/08835558838290347901noreply@blogger.com