从外部应用程序登录 Content Navigator

G_h*_*hi3 2 java http ibm-content-navigator

我正在尝试从我的 Java 应用程序(FileNet P8 中的事件操作处理程序)访问 Content Navigator 上的 PluginService。应用程序使用 JAXRS 登录服务security_token从 Content Navigator 服务器接收。但是,如果我尝试调用 PluginService,我会收到登录已过期的响应。

我能够获得安全令牌,如此代码块中所述:

URL logonUrl = new URL("http://icn-host:9081/jaxrs/logon"
    + "?userid=user"
    + "&password=password"
    + "&desktop=admin"
    + "&contextPath=%2Fnavigator");
HttpURLConnection logonConnection = (HttpURLConnection)logonUrl.openConnection();
logonConnection.setRequestMethod("POST");
logonConnection.setRequestProperty("Content-Type",
    "application/x-www-form-urlencoded");
logonConnection.setDoOutput(true);
InputStream logonResponse = logonConnection.getInputStream();
String responseText = IOUtils.toString(logonResponse, "UTF-8")
    .replaceFirst("^\\{}&&", "");
JSONObject responseJson = JSONObject.parse(responseText);
return (String)responseJson.get("security_token");
Run Code Online (Sandbox Code Playgroud)

但是当我尝试发出另一个请求时,我收到错误响应:

URL requestUrl = new URL("http://icn-host:9081/plugin.do"
    + "?plugin=myPlugin&action=myPluginService&myRequestProps=foobar");
HttpURLConnection requestConnection =
    (HttpURLConnection)requestUrl.openConnection();
requestConnection.setRequestMethod("GET");
String securityToken = getSecurityToken(); // calls above code
requestConnection.setRequestProperty("security_token", securityToken);
equestConnection.setDoOutput(true);
InputStream responseStream = requestConnection.getInputStream();
String responseText = IOUtils.toString(responseStream, "UTF-8")
    .replaceFirst("^\\{}&&", "");
log.info("response was: " + responseText);
Run Code Online (Sandbox Code Playgroud)

我总是得到以下回应:

{
  "messagesEncoded":true,
  "errors": [
    {
      "adminResponse":null,
      "moreInformation":null,
      "explanation":"Your session expired because of inactivity.",
      "number":"1003",
      "userResponse":"Log in again.",
      "text":"Your session expired."
    }
  ]
}
Run Code Online (Sandbox Code Playgroud)

我也试过设置 cookie,但没有成功。

java.net.CookieManager cookieManager = new java.net.CookieManager();
Map<String, List<String>> headerFields = logonConnection.getHeaderFields();
List<String> cookiesHeader = headerFields.get("Set-Cookie");
if (cookiesHeader != null) {
  for (String cookie : cookiesHeader) {
    cookieManager.getCookieStore().add(null, HttpCookie.parse(cookie).get(0));
  }
}

// ...

StringBuilder cookieHeader = new StringBuilder();
List<HttpCookie> cookies = cookieManager.getCookieStore().getCookies();

for (int i = 0; i < cookies.size(); i++) {
  if (i > 0) {
    cookieHeader.append(";");
  }

  HttpCookie cookie = cookies.get(i);
  log.info("Cookie " + i + ": " + cookie.toString());
  cookieHeader.append(cookie.toString());
}

requestConnection.setRequestProperty("Cookie", cookieHeader.toString());
Run Code Online (Sandbox Code Playgroud)

我尝试在内容导航器窗口中使用 XMLHttpRequest 复制请求,它按预期工作:

var xhr = new XMLHttpRequest();
xhr.open("GET", "plugin.do" +
    "?plugin=myPlugin" +
    "&action=myPluginService" +
    "&myRequestProps=foobar");
xhr.setRequestHeader("security_token", ecm.model.Request._security_token);
xhr.send();
Run Code Online (Sandbox Code Playgroud)

Ivo*_*ker 5

几个月前,我为一个客户遇到了类似的挑战,我必须自动化安装插件和应用 CI 配置的过程。

我发现在登录后获取桌面作为第一个 api 调用以使会话变为“有效”是关键。

所以首先是 jaxrs/logon,然后是 jaxrs/getDesktop,然后是你的服务调用。

一点旁注:如果您打算稍后进行容器管理的身份验证,则过程将有所不同。jaxrs/logon 将不起作用,取而代之的是 jaxrs/getDesktop 将提供 security_token。

不过有一点要注意:拥有一个共享库,您可以将它们从事件操作中用作 ICN 服务,这不是更好的解决方案吗?