<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Associating the auth ticket with a resource/ single use ? in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/associating-the-auth-ticket-with-a-resource-single-use/m-p/240536#M193666</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have a custom application that is calling into Alfresco to retrieve the documents from Alfresco. The custom client manages all the user authentication and authorization and interfaces with Alfresco using a single login. We are using webscripts to do the login and search. I would like to ensure that users cannot access Alfresco documents that are not presented to them via the application by trying to pass a different filename in the GET. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I noticed that the authentication-services-context.xml has a few properties under ticketComponent for ticketsExpire, oneOff, and expiryMode. I tried setting ticketsExpire to true and oneOff to true, too. Setting oneOff to true seems to cause issues on the web UI. In some cases I keep prompted for the login on every click. Is there a way to specify expiryMode etc… as part of the webscript call so that the user cannot use the same ticket to get a different document? Or, is there a different way to achieve this?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;TIA&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Nov 2009 16:58:03 GMT</pubDate>
    <dc:creator>shikarishambu</dc:creator>
    <dc:date>2009-11-24T16:58:03Z</dc:date>
    <item>
      <title>Associating the auth ticket with a resource/ single use ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/associating-the-auth-ticket-with-a-resource-single-use/m-p/240536#M193666</link>
      <description>I have a custom application that is calling into Alfresco to retrieve the documents from Alfresco. The custom client manages all the user authentication and authorization and interfaces with Alfresco using a single login. We are using webscripts to do the login and search. I would like to ensure tha</description>
      <pubDate>Tue, 24 Nov 2009 16:58:03 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/associating-the-auth-ticket-with-a-resource-single-use/m-p/240536#M193666</guid>
      <dc:creator>shikarishambu</dc:creator>
      <dc:date>2009-11-24T16:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Associating the auth ticket with a resource/ single use ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/associating-the-auth-ticket-with-a-resource-single-use/m-p/240537#M193667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;If you didn't use a proxy account you would not need to jump through hoops.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Can you get some sort of SSO working between your application and alfresco?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Nov 2009 17:14:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/associating-the-auth-ticket-with-a-resource-single-use/m-p/240537#M193667</guid>
      <dc:creator>mrogers</dc:creator>
      <dc:date>2009-11-24T17:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Associating the auth ticket with a resource/ single use ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/associating-the-auth-ticket-with-a-resource-single-use/m-p/240538#M193668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;The reason why we decided to use a proxy account rather than have user accounts in Alfresco is our application/ solution treats ECM as a pluggable component. So, we want the ability to manage access to the documents in our application (and, not have it replicated/ setup in the different ECM flavors that are out there). I realize that it does not make full use of an ECM's capabilities. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I could possibly get a SSO solution in place but it still will have to be a proxy/service account. I do think this is a valid integration scenario - accessing an external resource through a single service account. What I am trying to achieve is nothing more than stopping a replay attack in case of a web/ web service application.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Nov 2009 19:26:04 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/associating-the-auth-ticket-with-a-resource-single-use/m-p/240538#M193668</guid>
      <dc:creator>shikarishambu</dc:creator>
      <dc:date>2009-11-24T19:26:04Z</dc:date>
    </item>
  </channel>
</rss>

