Jazz Forum Welcome to the Jazz Community Forum Connect and collaborate with IBM Engineering experts and users

RTC 2.0.0.2 iFix 1 license key upload error

After upgrading to 2.0.0.2 iFix1 and starting with a clean slate by creating new tables in the repository, when we try to upload the license key we are getting the following message:

Error uploading License Activation key: The user has the roles required to perform this operation, but the permission has been denied because this request might have been forged by a malicous website. To prove that this request is not part of a CSRF attack add a new HTTP header with the name 'X-Jazz-CSRF-Prevent' and use the current JSESSIONID value as the value.

What could be the problem here? The RTC server is being hosted on WAS.

Thanks.

0 votes



11 answers

Permanent link
We are investigating.. stay tuned.

0 votes


Permanent link
@kmunir, can you give us more information on what server edition of 2.0.0.2 iFix2 and what platform are you using ?

0 votes


Permanent link
This seems like your browser is infected with virus, have you tried from a different machine ?

0 votes


Permanent link
In the 2.0.0.2 ifixes we have continued to add security enhancements to protect against various attacks.

What you are seeing is the server protecting itself against a specific kind of cross sign scripting attack.

If you are using the web UI from the same ifix server you should not be seeing the problem. is it possible that the web UI you have is stale, because of a browser cache issue? Can you try forcing a full reload of the page and try the upload again.

0 votes


Permanent link
@kmunir, can you give us more information on what server edition of 2.0.0.2 iFix2 and what platform are you using ?


RTC for Power - Standard edition - i5/OS V6R1.

0 votes


Permanent link
This seems like your browser is infected with virus, have you tried from a different machine ?


Yes, we are getting the same message.

0 votes


Permanent link
In the 2.0.0.2 ifixes we have continued to add security enhancements to protect against various attacks.

What you are seeing is the server protecting itself against a specific kind of cross sign scripting attack.

If you are using the web UI from the same ifix server you should not be seeing the problem. is it possible that the web UI you have is stale, because of a browser cache issue? Can you try forcing a full reload of the page and try the upload again.


We just tried. Still getting the message.

0 votes


Permanent link
Do you see the problem on non-I platforms using the same server fixpack?

0 votes


Permanent link
Do you see the problem on non-I platforms using the same server fixpack?


Have not tried this out yet.

0 votes


Permanent link
Do you see the problem on non-I platforms using the same server fixpack?

We finally loaded RTCp 2.0.0.2 ifix1 for Windows and was able to successfully upload the license from my browser.

Back on the i, I also got the same cross-scripting error when I tried to create a new project area. I was able to create the project area thought the RTCp eclipse client.

0 votes

1–15 items
page 1of 1 pagesof 2 pages

Your answer

Register or log in to post your answer.

Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.

Search context
Follow this question

By Email: 

Once you sign in you will be able to subscribe for any updates here.

By RSS:

Answers
Answers and Comments
Question details

Question asked: Apr 29 '10, 5:21 p.m.

Question was seen: 16,584 times

Last updated: Apr 29 '10, 5:21 p.m.

Confirmation Cancel Confirm