Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, August 31, 2015

You are not authorized to access this component. (40 20)

You may see this error message, even if you have granted correct security. To resolve this please run the below sql. Open the role and delete the orphan permission list or remove the role from the user and issue will be fixed.

This was happening as user has a role that had a permission list that did not existed in the database. This happens when the project is migrated to target database but does not include the permission list.

non-existing permission list assigned to the role.

Select R.rolename
, RC.classid
From psroleuser R
, psroleclass RC
Where RC.Rolename = R.Rolename
And not exists
(Select 'X' from psclassdefn C
Where C.classid = RC.classid)
And R.roleuser = '[--OPRID—]'

Original Post appeared in :

http://eliandokp.blogspot.com/2010/02/component-error-you-are-not-authorized.html

Monday, April 13, 2015

Running a BI Publisher Report from an online page logs user out of PIA

When user runs a BI Publisher Report from an online PIA page by clicking a button and this report is based on a Query, user sees the below message.

An error has occurred. You may attempt to sign in again. If your attempt fails, please contract your System Administrator.
Please make sure Webserver and Appserver are up. null

image

In the Appserver Log, we see the error

PSPAL: Abort: Unexpected signal received
PSPAL: Abort: Location: /vob/peopletools/src/pspal/exception_sigaction.cpp:494: RecoverableSignalHandler
PSPAL: Abort: Generating process state report to /opt/test/psft/pt/8.53/appserv/prd/LOGS/PSAPPSRV.10742/process_state.txt

Inside the process_state.txt, we see that RuntoFile is actually generating the exception and killing the appserver thread.

#2  0x00007f7012a8f224 in PSPAL::DumpProcessState::GenerateAbortDiagnostics(char const*, PSPAL::ExceptionContext*) () from /opt/test/tools/bin/libpspal64.so    #3  0x00007f7012a8386b in PSPAL::Abort(char const*, char const*, int, char const*, PSPAL::ExceptionContext*) () from /opt/test/tools/bin/libpspal64.so
   #4  0x00007f7012a89191 in PSPAL::SigactionSignalHandler::RecoverableSignalHandler(int, siginfo*, void*) () from /opt/test/tools/bin/libpspal64.so
   #5  0x00007f7012a89a65 in PSPAL::SigactionSignalHandler::SignalHandler(int, siginfo*, void*) () from /opt/test/tools/bin/libpspal64.so
   #6  0x00007f6ff6e15f12 in os::Linux::chained_handler(int, siginfo*, void*) () from /opt/test/tools/jre/lib/amd64/server/libjvm.so
   #7  0x00007f6ff6e1bbf6 in JVM_handle_linux_signal () from /opt/test/tools/jre/lib/amd64/server/libjvm.so
   #8  <signal handler called>
   #9  0x00007f700f03619f in QpmEnd () from /opt/test/tools/bin/libpssys.so
   #10 0x00007f70088b7815 in CPSQuery::CleanupQueryExecution(void*, void*) () from /opt/test/tools/bin/libpsoftapi.so
   #11 0x00007f70088fa777 in CPSQuery::RunToFile(IPSRecBuf*, wchar_t const*, int, int) () from /opt/test/tools/bin/libpsoftapi.so
   #12 0x00007f70088c28fc in _IPSQuery::InvokeMethod(wchar_t const*, IPSApiVariant*, IPSApiVariant**, int) () from /opt/test/tools/bin/libpsoftapi.so

Resolution: Please determine the Records used in PeopleSoft query that is used in BI Publisher Report definition. Please make sure that this record is added to permission list that belongs to the user running this report using Query tab in permission list component and accessing the Access group link. Once the permission list is modified add the permission list to the Role that is assigned to user if not already added. This resolves the issue. Noted this in PT 8.53.12.

Wednesday, April 03, 2013

Query to determine which records user can see

SELECT DISTINCT B.TREE_NODE, Z.RECDESCR
FROM PSTREEDEFN A,
PSTREENODE B,
PS_SCRTY_ACC_GRP C,
PSTREENODE E,
PSROLECLASS X,
PSROLEUSER Y,
PSRECDEFN Z
WHERE A.SETID = ' '
AND A.TREE_STRCT_ID = 'ACCESS_GROUP'
AND A.EFF_STATUS = 'A'
AND A.EFFDT =
(SELECT MAX (D.EFFDT)
FROM PSTREEDEFN D
WHERE D.SETID = ' '
AND D.TREE_NAME = A.TREE_NAME
AND D.EFFDT <=
TO_DATE (TO_CHAR (SYSDATE, 'YYYY-MM-DD'),
'YYYY-MM-DD'
))
AND Y.ROLEUSER = :1
AND Y.ROLENAME = X.ROLENAME
AND X.CLASSID = C.CLASSID
AND C.TREE_NAME = A.TREE_NAME
AND C.ACCESSIBLE = 'Y'
AND B.SETID = ' '
AND B.TREE_NAME = E.TREE_NAME
AND B.EFFDT = E.EFFDT
AND B.TREE_NODE_TYPE = 'R'
AND B.TREE_NODE = Z.RECNAME
AND Z.RECTYPE IN (0, 1, 6)
AND E.SETID = ' '
AND E.TREE_NAME = A.TREE_NAME
AND E.EFFDT = A.EFFDT
AND E.TREE_NODE_TYPE = 'G'
AND B.TREE_NODE_NUM BETWEEN E.TREE_NODE_NUM AND E.TREE_NODE_NUM_END
AND C.ACCESS_GROUP = E.TREE_NODE
AND ( (NOT EXISTS
(SELECT 'X'
FROM PS_SCRTY_ACC_GRP F
WHERE F.CLASSID = X.CLASSID
AND F.TREE_NAME = A.TREE_NAME
AND F.ACCESSIBLE = 'N'))
OR (E.TREE_NODE_NUM =
(SELECT MAX (G.TREE_NODE_NUM)
FROM PSTREENODE G, PS_SCRTY_ACC_GRP H
WHERE G.SETID = ' '
AND G.TREE_NAME = A.TREE_NAME
AND G.EFFDT = A.EFFDT
AND G.TREE_NODE_TYPE = 'G'
AND B.TREE_NODE_NUM BETWEEN G.TREE_NODE_NUM
AND G.TREE_NODE_NUM_END
AND H.CLASSID = X.CLASSID
AND H.TREE_NAME = A.TREE_NAME
AND H.ACCESS_GROUP = G.TREE_NODE)))

Wednesday, September 15, 2010

Invalid signon time for user PS@xyx.com

when user tries to signon they get the following message on the Login Page.

Invalid signon time for user

 

This message is thrown due to a  blank classid row in PSROLECLASS table. Use the following SQL to determine the Cause.
select * from psroleclass where  classid = ' '

To fix this, run this SQL.
delete from psroleclass where  classid = ' '

No Appserver or Webserver bounce was required.

This was tested in 8.50.10

Thursday, March 25, 2010

PeopleTools 8.4x/8.1 ERD Diagram for Security tables

On Metalink Go to Knowledgebase article : 611947.1 : PeopleTools 8.x Security Relationship Diagrams

The above document provides the ERD diagram for peopletools security table.

Friday, April 11, 2008

Schedule Query Security Access

Access to Schedule Query is controlled by the following.

1. Schedule Query Component
2. Access to PSQUERY App engine process.

There are 2 ways you can run  schedule Query process.

1. From Query Manager or Query viewer: These pages uses SCHED_QUERY_QRYVW (SCHEDQUERY2) Component with different search record: QUERY_RUN_QRYVW
2. From Schedule Query: This page uses SCHED_QUERY (SCHEDQUERY) Component with search record: QUERY_RUN_CNTRL

Following Process Groups are assigned to the PSQUERY App engine process that is used for scheduling queries.
TLSALL

select * from PS_PRCSDEFNGRP where prcsname = 'PSQUERY'

Therefore to Grant access to all users for Scheduling Queries who have access to Query Manager or Query Viewer Component following must be done.

1. Add access to Component : SCHED_QUERY (Baritemname: SCHEDQUERY) and SCHED_QUERY_QRYVW (Baritemname: SCHEDQUERY2)
2. Add Process groups to Same permission list that grants access to Schedule query: TLSALL

In Demo, PTPT1000 Classid and Role PeopleSoft user has access to the components

SCHED_QUERY (Baritemname: SCHEDQUERY) and SCHED_QUERY_QRYVW (Baritemname: SCHEDQUERY2)

In Demo, PTPT1200 Classid and Role PeopleTools has access to TLSALL Process group which can run PSQUERY Process.

Therefore, user must have access to PTPT1000 and PTPT1200 permission list. Therefore Role PeopleTools and PeopleSoft user must be assigned to successfully run the Schedule Query process using delivered Pages.

If you are creating a custom permission list, you can assign access to these components and process group to same permission list. Assign the permission list to a role and assign it to actual user.

Your users may get this error message, if they do not have access to process group assigned to PSQUERY Process and try to schedule the query.

PeopleSoft error report: Error: Required ProcessRequest attribute missing: JobName (65,151) PRCSRQSTDLG_WRK.LOADPRCSRQSTDLGPB.FieldFormula  Name:LaunchAndRunProcessRequest  PCPC:67779  Statement:768 Called from:PRCSRQSTDLG_WRK.LOADPRCSRQSTDLGPB.FieldFormula  Name:LaunchProcessRequestDlg  Statement:787 Called from:QUERY_RUN_CNTRL.QRYNAME.SavePreChange  Statement:2

This error normally means user is not having access to Job or process group assigned to the process or job name. You can use these queries to determine what process groups are assigned to a job or process definition and what permission list has access to it.

select * from PS_PRCSDEFNGRP where prcsname = 'PSQUERY'
select * from PS_PRCSJOBGRP where PRCSJOBNAME = '3CBL'
select * from psauthprcs where prcsgrp = 'TLSALL'