934 Views 11 Replies Last post: Jan 14, 2009 8:47 AM by Chrisbrenschmidt RSS
Walter Gildersleeve Jive Employee 381 posts since
Sep 29, 2008
Currently Being Moderated

Jan 12, 2009 9:46 AM

un-protecting RSS feeds not working

Hi,

 

We're having trouble opening up the RSS feeds to unauthorized access.  Currently, feeds are set to be open (Admin > System > Settings > Feeds > Basic Authentication set to Off), yet unauthorized access attempts result in a auth window popping up.

 

I've tested this on out-of-the-box CS and switching back-and-forth works fine.  Will it require a restart of the app?  Perhaps this is an issue with CSC 2.5.3 that's been fixed in later versions?

 

Walter

Tags: rss, clearspace_community, acs
scott.hirdes Jive Employee 3,311 posts since
Oct 9, 2007
Currently Being Moderated
Jan 12, 2009 11:33 AM in response to: Walter Gildersleeve
Re: un-protecting RSS feeds not working

What is the jive.auth.disallowGuest system property set to on the instance?

 

Is there an SSO filter in place for the instance?

scott.hirdes Jive Employee 3,311 posts since
Oct 9, 2007
Currently Being Moderated
Jan 12, 2009 1:27 PM in response to: Walter Gildersleeve
Re: un-protecting RSS feeds not working

Can you provide the URL for the RSS feed that is having trouble so that I can test with it locally?

scott.hirdes Jive Employee 3,311 posts since
Oct 9, 2007
Currently Being Moderated
Jan 12, 2009 2:31 PM in response to: Walter Gildersleeve
Re: un-protecting RSS feeds not working

The problem is the permissioning of the Spaces.

 

The way the permissions are currently setup in the admin console, only registered users can view anything.  The space permissions on the root community do not allow the "Anyone" user to view spaces or content within spaces.  So, when the anonymous RSS feed request comes through, it tries to load up a community that cannot be viewed by a guest and the result is the auth request that is being seen.

 

To avoid this, the "Anyone" permissions line should have permission to view spaces and read content within the spaces.  The jive.auth.disallowGuest system property will control whether non registered users will be forced to login to the instance or not.

Chrisbrenschmidt Novice 178 posts since
Sep 3, 2008
Currently Being Moderated
Jan 13, 2009 6:04 AM in response to: scott.hirdes
Re: un-protecting RSS feeds not working

Let me see if I understand this....

 

If we give "anyone" access to view the space and to read the document and comments, then the feed works. They then click on a link and a Jive community page appears. Then because of SSO, they get redirected to the login page.

 

The one little wrinkle on this is a security pop-up box appears before the Jive page can fully render and redirect to the ACS login. I've attached a screenshot. I don't think this is too serious as they can't really capture this page or click on any links.

 

RSS_feed_test.png

scott.hirdes Jive Employee 3,311 posts since
Oct 9, 2007
Currently Being Moderated
Jan 13, 2009 4:30 PM in response to: Chrisbrenschmidt
Re: un-protecting RSS feeds not working

I believe the cause of that message is that there is a widget on that page that contains an image whose source comes from a URL that is not an https URL.

 

The widget is the one with the title "ES&T at the AGU Fall Meeting."  At the bottom of that widget there is an image (that looks like text) that says "comments".  This image is sourced from the URL http://feeds.wordpress.com/1.0/comments/estagu.wordpress.com/84/ which is not using SSL.  Because the ACS site is using SSL, IE will give the warning you see if it loads something from a non-SSL URL in loading the page.

Chrisbrenschmidt Novice 178 posts since
Sep 3, 2008
Currently Being Moderated
Jan 14, 2009 5:20 AM in response to: scott.hirdes
Re: un-protecting RSS feeds not working

I understand the popup issue. The problem I was really concerned about was the redirecting from a Jive Page (which was not supposed to be accessible) back to the login page.

 

I think we're  in the process of trying to fix/understand all that now.

scott.hirdes Jive Employee 3,311 posts since
Oct 9, 2007
Currently Being Moderated
Jan 14, 2009 8:44 AM in response to: Chrisbrenschmidt
Re: un-protecting RSS feeds not working

Is this still happening?  When I try to access the URL for the community in your example, I am immediately redirected to the login page without seeing the community page.

Chrisbrenschmidt Novice 178 posts since
Sep 3, 2008
Currently Being Moderated
Jan 14, 2009 8:47 AM in response to: scott.hirdes
Re: un-protecting RSS feeds not working

No. I think we are okay now.

C

More Like This

  • Retrieving data ...

Bookmarked By (0)