ofbiz-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Ashish Repal <ashishre...@gmail.com>
Subject Re: getting exception in calling the service
Date Sat, 25 Jul 2015 11:31:33 GMT
Actually this is a listing screen where i have provided hyperlinks using
href.
Eg. in ftl
<td><a
href="/facility/control/ModifyShipmentStatus?shipId=${tripShipmentData.shipId?if_exists}&amp;status=Delivered"
class="buttontext">Delivered</a></td>

and in Form.xml

        <field name="start" position="2" title="" widget-style="buttontext"
use-when="&quot;N&quot;.equals(isStarted)"  >
             <hyperlink target="/startShip" description="start Ship"  >
                <parameter param-name="tripId" value="${shipId}"
/>
            </hyperlink>
        </field>


Regards,
Aashish Repal
09623381664

On Sat, Jul 25, 2015 at 1:00 PM, Adrian Crum <
adrian.crum@sandglass-software.com> wrote:

> Basically, you need to invoke the URL with an HTTP POST instead of an HTTP
> GET.
>
> Adrian Crum
> Sandglass Software
> www.sandglass-software.com
>
>
> On 7/24/2015 11:04 PM, Ashish Repal wrote:
>
>> Hi All,
>> I am getting below exception when calling the service from controller.
>>
>> [ServiceEventHandler.java:408:ERROR] =============== Found URL parameter
>> [shipId] passed to secure (https) request-map with uri
>> [ModifyShipmentStatus] with an event that calls service
>> [ModifyShipmentStatus]; this is not allowed for security reasons! The data
>> should be encrypted by making it part of the request body (a form field)
>> instead of the request URL.
>>
>> anyone has idea about this?
>>
>> controller.xml:
>>
>>      <request-map uri="ModifyShipmentStatus">
>>           <security https="true" auth="true" />
>>          <event type="service" path="" invoke="ModifyShipmentStatus"/>
>>          <response name="success" type="view" value="EditTrip"/>
>>          <response name="error" type="view" value="EditTrip"/>
>>      </request-map>
>>
>> If I comment the security tag in controller it works but later it fails
>> saying
>>
>> org.ofbiz.webapp.control.RequestHandlerException: Not accepting insecure
>> form data posted to a secure request
>>
>>
>>
>> Regards,
>> Aashish Repal
>> 09623381664
>>
>>

Mime
  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message