Want to get rid of Google Ads, click here.
+ Reply to Thread
Results 1 to 13 of 13

Thread: SM7 Web Admin forms for any user

  1. #1
    Member
    Join Date
    Feb 2008
    Location
    Hamilton, ON, Canada
    Posts
    79

    Default SM7 Web Admin forms for any user

    Hi all,
    We recently setup SM7 and discovered an issue when using the web interface. If a user attempts to login with an admin account, say "falcon", and fails with a bad password. Then use a regular account, with out changing the screen. All the admin forms for the falcon account are accessible. Most will actually work, like scheduling a system shutdown. Did we miss a configuration, or is it a "feature" of SM7
    connect URL is
    /[server]:8080/webtier-7.00/index.do

    Thanks

  2. #2
    Administrator tommy's Avatar
    Join Date
    Nov 2001
    Location
    Copenhagen
    Posts
    4,272

    Default

    From your description I am not able to reproduce that.
    Best regards Tommy
    Blog - - ITIL certified - Accredited Integration Specialist – HP OpenView Service Management

    Want to keep this site alive? Consider making a donation. Click here.

  3. #3
    Senior Member benvargas's Avatar
    Join Date
    Apr 2005
    Location
    San Diego, CA USA
    Posts
    194

    Default

    I too am unable to replicate this...

    01. Try to login to http://xxxxxxxxx/webtier-7.00/index.do as falcon with incorrect pass.
    02. After "Invalid Login" message, successfully login as BOB.HELPDESK

    BOB.HELPDESK's forms are displayed in the system navigator as expected. Can you elaborate on what your steps if they're different than above?

  4. #4
    Member
    Join Date
    Feb 2008
    Location
    Hamilton, ON, Canada
    Posts
    79

    Default

    I suspect we may have missed something with the accounts setup.

    I have attached a document that shows how I was loggin in with pics of what was displayed for clarity. We do not have the BOB.HELPDESK account so something is different with our installation.

    Thanks
    Attached Files

  5. #5
    Administrator tommy's Avatar
    Join Date
    Nov 2001
    Location
    Copenhagen
    Posts
    4,272

    Default

    Don't worry about the user BOB.HELPDESK thats just a user in the default system which just has been deleted in your system. I used CM 1 for example.

    Check the operator home menu, if for some reason the menu specified is not found SC defaults to the admin home menu. It might be whats happening.
    Best regards Tommy
    Blog - - ITIL certified - Accredited Integration Specialist – HP OpenView Service Management

    Want to keep this site alive? Consider making a donation. Click here.

  6. #6
    Member
    Join Date
    Feb 2008
    Location
    Hamilton, ON, Canada
    Posts
    79

    Default

    This condition exist for every account I have setup. But I thought we were OK based on Pic1 which shows the correct menu.

    I will check

    Thanks

  7. #7
    Senior Member benvargas's Avatar
    Join Date
    Apr 2005
    Location
    San Diego, CA USA
    Posts
    194

    Default

    Since the user "Service Desk" logs in and gets the menu initially, it seems the menu must be setup correctly.

    If you do it the opposite way... fail login with Service Desk and then correctly login as falcon, does falcon get the Service Desk menu?

  8. #8
    Member
    Join Date
    Feb 2008
    Location
    Hamilton, ON, Canada
    Posts
    79

    Default

    mm, good point I never tried in reverse.
    So...
    1) Logged in as Service Desk using a password, caused a failure. (this account has no password)
    2) logged in as falcon using the password.
    3) Menu displayed matches the falcon account.

    Conclusion, the answer is no. The falcon account is fine.

    Also, I have submitted an Incident with HP this morning (ID 3601133557).

  9. #9
    Senior Member benvargas's Avatar
    Join Date
    Apr 2005
    Location
    San Diego, CA USA
    Posts
    194

    Default

    Please keep us up to date on what happens!

  10. #10
    Administrator tommy's Avatar
    Join Date
    Nov 2001
    Location
    Copenhagen
    Posts
    4,272

    Default

    Can you make an unload of following and attach here:

    - formatctrl login.DEFAULT
    - an operator that fails with password set to either the userid or blank
    - the menu specified on the operator
    - the format for the menu
    Best regards Tommy
    Blog - - ITIL certified - Accredited Integration Specialist – HP OpenView Service Management

    Want to keep this site alive? Consider making a donation. Click here.

  11. #11
    Member
    Join Date
    Feb 2008
    Location
    Hamilton, ON, Canada
    Posts
    79

    Default

    Update.
    HP has moved this up to the developers for action.
    They were able to replicate the condition with the BOB.HELPDESK account. To replicate the condition, modify the operator record for BOB.HELPDESK. Change the startup routines to use the falcon operators menu. Be sure to set all the parameters the same as well.
    Some access is still restricted, but you will have sufficient rights to create a new operator and assign sysadmin rights using the sys admin role. Then gain full access with the new account.

  12. #12
    Senior Member glg's Avatar
    Join Date
    Aug 2004
    Location
    Chicago, IL, USA
    Posts
    714

    Default

    BOB.HELPDESK isn't supposed to have falcon's menu. The menu is how you restrict access to many functions in the system.

  13. #13
    Administrator tommy's Avatar
    Join Date
    Nov 2001
    Location
    Copenhagen
    Posts
    4,272

    Default

    Quote Originally Posted by glg View Post
    BOB.HELPDESK isn't supposed to have falcon's menu. The menu is how you restrict access to many functions in the system.
    I agree. Give a normal user the admin menu and you ask for trouble. I am surprised HP even bothered to raise a ticket and investigate further on it.

    So my answer had I been in HP's end: Works as designed!
    Best regards Tommy
    Blog - - ITIL certified - Accredited Integration Specialist – HP OpenView Service Management

    Want to keep this site alive? Consider making a donation. Click here.

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts