Accessing protected resources with access token
 
			 Hello,
After implementing an OAuth dance and retrieving the access token/secret pair, I have been trying to use it to access protected resources. My request is of the type:
- Consumer key
- Consumer secret
- access token
- access token secret
2 answers
 
								Hi
Comments
 
				Hello,
 
				 
				Or for JAS when the auth is complete you have cookies JSA_AUTH_COMPLETE, JSA_SESSION_IDENTITY and JSESSIONID (i.e. there is no JAZZ_AUTH_TOKEN cookie)
 
				Hmm, I've just checked on a different server near me and it returns 400 from https://SERVER:PORT/rm/pubish/resources/* and I know the authentication I'm using works on that server - so check this on your server by opening the url in a browser, If publishing isn't disabled/blocked this should give some XML results - if it gives a 400 then I guess the publish service is disabled/blocked.
 
				Thank you for all the help, you were right that the authorization wasn't working, I had unknowingly skipped a part of the process, was operating under the assumption that by running the authorization request on the JTS server, that no user interaction was necessary, since I was obtaining a pair of access key/secret. This was false, I still had to access the page manually and authorize the request token (?), after doing so, I was able to access the protected resources easily.
 
								If you log into RM as a client, as far as I know, you have to do that against JTS and not RM. The reason is that RM delegates its authentication to JTS (other than EWM, ETM).
Comments
 
				The authentication is done on JTS, specifically
https://IP:PORT/jts/oauth-request-token 
https://IP:PORT/jts/oauth-authorize?oauth_token=TOKEN&Authorize=True
https://IP:PORT/jts/oauth-access-token
as per https://jazz.net/wiki/bin/view/Main/JFSCoreSecurity#Application_Authentication
Comments
Ian Barnard
FORUM ADMINISTRATOR / FORUM MODERATOR / JAZZ DEVELOPER Jun 23 '21, 3:06 p.m.See my answer