B Replacement Data; Data Security; Appendix B, "Replacement Data; B.1 Data Security - Novell IDENTITY MANAGER 3.6.1 - MANUAL TASK SERVICE DRIVER Implementation Manual

Manual task service driver implementation
Table of Contents

Advertisement

Replacement Data
B
Replacement data is used with XML documents used as templates to construct e-mail messages,
Web pages, and XDS documents. The actual replacement is accomplished by processing the
template document with an XSLT style sheet that performs the replacement as part of constructing
the output document.
Replacement data is supplied to the Manual Task Service driver through different mechanisms on
the Subscriber and Publisher channels.
Subscriber Channel
Replacement data is supplied as part of the <mail> element.
Part of the supplied replacement data can be URL data. If URL data is supplied, it is processed
and completed and replaced by automatic data items (see
Replacement Data Items," on page
If the
element specifies that an association value should be constructed (that is, the
<mail>
element has a src-dn attribute), an automatic data item named "association" is added to
<mail>
the replacement data.
Publisher Channel
Replacement data is supplied in the HTTP URL data and HTTP POST data.
Automatic URL replacement data items are added to the replacement data before it is used in
template processing.
Replacement data is presented during template processing as an XML document. The replacement
data document is passed to the style sheet processing the template as a parameter named
replacement-data. If no template is used, the XML document is processed directly by the style sheet.
Section B.1, "Data Security," on page 41
Section B.2, "XML Elements," on page 42

B.1 Data Security

Data items are passed from the Subscriber channel to the Publisher channel via a URL contained in
the e-mail sent by the Subscriber channel. Changing certain data items in the URL represents a
security threat. For example, if the responder-dn values in the URL supplied by the Subscriber
channel in the URL are replaced by another user's DN in the URL submitted to the Publisher
channel Web server, it would allow an unauthorized user to change data in eDirectory
To ensure that the data in the submitted URL is the same as the data originally supplied by the
Subscriber channel, protected data is provided. Protected data is data that cannot be changed for
security reasons. This data varies by configuration but always includes the responder-dn data items,
and data items corresponding to any eDirectory objects whose values are to be changed.
Appendix C, "Automatic
47).
B
.
TM
Replacement Data
41

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the IDENTITY MANAGER 3.6.1 - MANUAL TASK SERVICE DRIVER and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Identity manager 3.6.1

Table of Contents