==============================================================================
  DMC-2026 PERMISSION SCOPING PROBE -- READ-ONLY
==============================================================================

  QUESTION
    When Content Server is asked for a folder listing using a ticket obtained by
    impersonating a user, does it return what THAT USER may see?

    That and nothing else. This probe does not test the contents of the listing, how
    it is paged, or anything about categories.

  WHAT IT DOES TO THE ESTATE
    Nothing. It authenticates, and it reads one folder listing twice. It creates,
    changes and deletes nothing, and it does not contact any database.

  RUN
    started        : 2026-10-01 16:27:48 +01:00
    machine        : IMLAPTOP24
    OTDS           : http://blubaker.co.uk:8002/otdsws/rest
    Content Server : http://blubaker.co.uk/OTCS24ORA/cs.exe/api/
    service account: Chuck
    password       : typed at the console, not echoed and not recorded
    partition      : Content Server Members

  FIXTURE AS NOMINATED
    user A         : Ashlee   (expected to SEE the node below)
    user B         : John Boy   (expected NOT to see it)
    folder         : 152286
    node in it     : 170587

==============================================================================
  STEP 1 of 6   Authenticate the service account to OTDS
==============================================================================

  POST http://blubaker.co.uk:8002/otdsws/rest/authentication/credentials
    identifier form : partition-qualified
    body            : userName plus password (password not shown, here or anywhere)
    RESULT          : HTTP 200 OK
    ticket          : issued, 713 characters (value not shown)
    -> the service account authenticated to OTDS.

==============================================================================
  STEP 2 of 6   Check the prerequisites before touching a test user
==============================================================================
These are settings in OTDS. Meeting one halfway through a run, as an error raised
by a test user, is how a prerequisite gets mistaken for a result.

  GET  http://blubaker.co.uk:8002/otdsws/rest/currentuser   (is this account an OTDS administrator?)
    RESULT          : HTTP 200 OK
    isAdmin         : true
    isSysAdmin      : true
    -> permitted to impersonate, as far as OTDS reports.

  GET  http://blubaker.co.uk:8002/otdsws/rest/resources   (which OTDS resource is Content Server, and may it impersonate?)
    RESULT          : HTTP 200 OK
    resources       : 1 listed, 1 of type 'cs'
    resource        : 'Content Server'   (id 4a6091a9-0833-5424-6a0e-9aaab07ffe85)
    impersonation   : false
    -> "Allow impersonation" is off on this resource. Noted here; it does not stop
       the run. An OTDS administrator has been verified to impersonate with it off,
       so it is not something this probe needs.

  --- pre-flight: Chuck, the account this probe signed in with ---
  POST http://blubaker.co.uk:8002/otdsws/rest/authentication/ticketforuser   (impersonate)
    identifier form : partition-qualified
    RESULT          : HTTP 200 OK
    OTDS ticket     : issued, 1278 characters (value not shown)
    -> accepted in the partition-qualified form.
  GET  http://blubaker.co.uk/OTCS24ORA/cs.exe/api/v1/auth   (exchange for a Content Server ticket)
    RESULT          : HTTP 500 InternalServerError
    headers returned: Cache-Control, Content-Length, Content-Security-Policy, Content-Type, Date, Expires, Pragma, Server, X-Frame-Options, X-Powered-By
    OTCSTicket header present: no
    server message  : User does not have sufficient privileges to log-in while Content Server is in administration mode.
    -> this names ADMINISTRATION MODE. Content Server admits administrators only,
       so no session can be issued for an ordinary user. Precondition failure.
    -> no Content Server session for this account: User does not have sufficient privileges to log-in while Content Server is in administration mode.
       Content Server named ADMINISTRATION MODE, which is a setting on the estate
       and not the ordinary case of an OTDS administrator who is simply not a
       Content Server user. Carried to P1 below, which reports on the mode.
    privilege reads : from each test user's own session (Content Server may decline to report them)

==============================================================================
  STEP 3 of 6   Obtain a Content Server ticket for each test user
==============================================================================
No password is needed for either test user, and none is asked for. That is the point
of impersonation: the service account vouches for them by name.

  --- user A: Ashlee ---
  POST http://blubaker.co.uk:8002/otdsws/rest/authentication/ticketforuser   (impersonate)
    identifier form : partition-qualified
    RESULT          : HTTP 200 OK
    OTDS ticket     : issued, 1290 characters (value not shown)
    -> accepted in the partition-qualified form.
  GET  http://blubaker.co.uk/OTCS24ORA/cs.exe/api/v1/auth   (exchange for a Content Server ticket)
    RESULT          : HTTP 500 InternalServerError
    headers returned: Cache-Control, Content-Length, Content-Security-Policy, Content-Type, Date, Expires, Pragma, Server, X-Frame-Options, X-Powered-By
    OTCSTicket header present: no
    server message  : User does not have sufficient privileges to log-in while Content Server is in administration mode.
    -> this names ADMINISTRATION MODE. Content Server admits administrators only,
       so no session can be issued for an ordinary user. Precondition failure.

  --- user B: John Boy ---
  POST http://blubaker.co.uk:8002/otdsws/rest/authentication/ticketforuser   (impersonate)
    identifier form : partition-qualified
    RESULT          : HTTP 200 OK
    OTDS ticket     : issued, 1302 characters (value not shown)
    -> accepted in the partition-qualified form.
  GET  http://blubaker.co.uk/OTCS24ORA/cs.exe/api/v1/auth   (exchange for a Content Server ticket)
    RESULT          : HTTP 500 InternalServerError
    headers returned: Cache-Control, Content-Length, Content-Security-Policy, Content-Type, Date, Expires, Pragma, Server, X-Frame-Options, X-Powered-By
    OTCSTicket header present: no
    server message  : User does not have sufficient privileges to log-in while Content Server is in administration mode.
    -> this names ADMINISTRATION MODE. Content Server admits administrators only,
       so no session can be issued for an ordinary user. Precondition failure.

==============================================================================
  VERDICT
==============================================================================

  CANNOT CONCLUDE -- Content Server is in ADMINISTRATION MODE.

  Content Server refused to issue a session for an ordinary test user, naming the
  mode in its own words.

  In this mode Content Server admits administrators only, so no session can be
  obtained for an ordinary user and the comparison cannot be made at all.

  THIS IS NOT A RESULT ABOUT PERMISSIONS, and it is not a fault in your fixture. The
  folder, the item and the two test users may all be exactly right; none of them has
  been tested yet.

  To fix it: take Content Server out of administration mode -- it is usually left
  there after maintenance, or while a licence is being renewed -- and run the probe
  again. Nothing else needs changing, and nothing here was changed.

  The server's own message is in step 3 above.

  This is NOT a finding that permissions are broken. The probe stopped because it
  could not obtain evidence either way, and saying so is the honest outcome.

==============================================================================
  END OF REPORT
==============================================================================

  This file was checked before it was written: no session tickets, no password, and no
  raw response headers or bodies appear anywhere in it. Redactions applied: 0.

  Please send this file to Ian Morrison, imorrison@blubaker.com.

