Get error messages when user fails authentication in a custom loginportlet - Websphere

This is a discussion on Get error messages when user fails authentication in a custom loginportlet - Websphere ; I create a custom login portlet based on sample http://www-1.ibm.com/support/docview...id=swg21293879 But I don't know how to catch error message when a user fails authentication....

+ Reply to Thread
Results 1 to 7 of 7

Thread: Get error messages when user fails authentication in a custom loginportlet

  1. Get error messages when user fails authentication in a custom loginportlet

    I create a custom login portlet based on sample http://www-1.ibm.com/support/docview...id=swg21293879



    But I don't know how to catch error message when a user fails authentication.

  2. Re: Get error messages when user fails authentication in a customlogin por

    what kind of error do you want to display?



    such as invalid userid invalid password?





    IBM Certified System Administrator -- WebSphere Portal V6.0, V5.1, V5.0

    IBM Certified Solution Developer -- WebSphere Portal V5.1, v6.0



    The postings on this site are my own and do not necessarily represent the positions, strategies, or opinions of IBM

  3. Re: Get error messages when user fails authentication in a customlogin por

    Yes James, I want to know if a user puts invalid userid / invalid password


    I want to catch message like

    'EJPAK0004W: Login failed. Please enter a valid user ID and password.'


    Thanks for your help.

  4. Re: Get error messages when user fails authentication in a customlogin por

    well right now it only throws back an error, you will need to Customize the LoginUserAuth to throw your own exception





    IBM Certified System Administrator -- WebSphere Portal V6.0, V5.1, V5.0

    IBM Certified Solution Developer -- WebSphere Portal V5.1, v6.0



    The postings on this site are my own and do not necessarily represent the positions, strategies, or opinions of IBM

  5. Re: Get error messages when user fails authentication in a customlogin por

    Hi



    you can follow the exception chain to check the root cause, but from a security perspective you should not expose the information that the password is incorrect as in this case you expose that the userid is valid. This information can be used by an attacker to gain access information

  6. Re: Get error messages when user fails authentication in a customlogin por

    Hi Jim / Stefan_Schmitt



    Can you be more explicit. Some example should help.



    Thanks.

  7. Re: Get error messages when user fails authentication in a customlogin por

    Hi Jim



    I already customize the LoginUserAuth, and if a user didn't a special tag(value populated in LDAP) I redirect to Login Page again

    aRunData.setRedirectURL(redirectUrl.toString());



    But I need do to pass a message, to show user, something like (You don't have permissions, please contact your department manager)

    It is possible to pass some value to "Login Page"...

+ Reply to Thread