IBM Support

PM61452: PROVIDE CUSTOM PROPERTY TO IGNORE COMMITTED RESPONSE IN WSSERVLETRESPONSECALLBACK

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Provide custom property to ignore committed
    response in WSServletResponseCallback
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server V8.0                                 *
    ****************************************************************
    * PROBLEM DESCRIPTION: Provide an option to tell WebSphere     *
    *                      to supress illegalStateException        *
    *                      when committed Http Response is found.  *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    A custom loginModule can gain access to http response by
    calling
    com.ibm.wsspi.security.auth.callback.WSServletResponseCallback.
    When a custom loginModule commits http response in an attempt
    to show user-friendly error message on user's browser,
    WebSphere detects the committed response and throws
    illegalStatusExcepiton.
    Due to the error, the browser would show generic 403 error.
    The messages created by the custom loginModule would not reach
    the browser.
    

Problem conclusion

  • This apar introduced a toplevel security custom property :
    
      com.ibm.websphere.security.allow.committed.response
    
    When this property is set to true, WebSphere does not
    throw illegalStateException when committed http response is
    found.
    
    This will help custom message in the http response set by the
    loginModule to be displayed on the end user's browser.
    
    APAR PM61452 is currently targeted for inclusion in
    Fix Packs 8.0.0.5 and 8.5.0.2 of WebSphere Application
    Server.
    
    Please refer to the Recommended Updates page for delivery
    information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    
    In addition, please refer to URL:
    http://www.ibm.com/support/docview.wss?rs=404&uid=swg27006970
    for Fix Pack PTF information.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM61452

  • Reported component name

    WEBSPHERE FOR Z

  • Reported component ID

    5655I3500

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2012-03-28

  • Closed date

    2012-08-16

  • Last modified date

    2012-08-17

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE FOR Z

  • Fixed component ID

    5655I3500

Applicable component levels

  • R800 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"800","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
28 October 2021