IBM Support

LI81940: FORBIDDEN ERROR WHEN ATTEMPTING TO ADD MEMBER - USER HAS MEMBER:MANAGE PERMISSIONS

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • You get a forbidden error when attempting to add a member to
    catalog when being an user who has member:manage permissions
    Invite member works ok
    Setup :
    1- A catalog with space enabled. (eg catalog1 with space1).
    2- A custom role (custom-role1) with 'members:manage'
    permission only.
    3- An user (user1) who is a new member (added or invited) to
    catalog space (space1)
    4- User1 should not be a member at the catalog or pOrg level.
    5- User1 should have the custom role (custom-role1)
    Steps to reproduce:
    User1 navigates to his space (space1) in API manager
    User1 goes to the menu Members -> Add button -> Add member
    Result:
    The system returns error 403 Forbidden
    3- User1 is stuck on this page, the UI does not return to the
    previous page, user has to use the backwards button of the
    browser to leave the page.
    4- User1 invites a new member to the space
    This works as expected.
    

Local fix

  • Use invite instead of adding the user.
    

Problem summary

  • User receives forbidden error when attempting to "Add member" to
    catalog even though they have member:manage permissions.
    
    "Invite member" works successfully.
    

Problem conclusion

  • Fix is included in 2018.4.1.17 and 10.0.3, targeted for
    10.0.1.4.
    

Temporary fix

Comments

APAR Information

  • APAR number

    LI81940

  • Reported component name

    API CONNECT ENT

  • Reported component ID

    5725Z2201

  • Reported release

    18X

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-01-19

  • Closed date

    2021-08-05

  • Last modified date

    2021-08-05

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    API CONNECT ENT

  • Fixed component ID

    5725Z2201

Applicable component levels

  • R18X PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSMNED","label":"IBM API Connect"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"18X","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
29 September 2021