[#1155] Fix typos, unresolved placeholders and dead ForgeRock links in the guides - #1157
Conversation
…ad ForgeRock links in the guides
- Fix the hhttps typo in the mobile samples link
- Enable attribute substitution in the three console blocks that showed {openam-version} literally
- Close the unterminated example block in Getting Started, which swallowed the "Trying It Out" section
- Drop the stray bold markers around the self-service email examples and keep them as literals
- Replace or remove the links to backstage.forgerock.com and forgerock.org, which no longer serve this content
Fixes OpenIdentityPlatform#1155
maximthomas
left a comment
There was a problem hiding this comment.
praise: The fixes land on the actual rendering defects, and the replacement links point at things that exist.
getting-started/chap-first-steps.adocgets the missing====closer, so the rest of the chapter no longer renders as<p>=== Trying It Out</p>.- The new
openam-sampleslinks resolve on master:openam-samples/custom-authentication-module,policy-evaluation-pluginandsts-example-codeall exist, and the STS path indev-guide/chap-sts.adocnow matches the last one. subs="attributes+"is added to exactly the three blocks that showed{openam-version}literally (install-guide/chap-install-tools.adoc:70,:303, anddev-guide/chap-client-dev.adoc).
issue (non-blocking): The description says com.iplanet.am.jssproxy.trustAllServerCerts "only disables host name verification … it does not trust the certificate". That is not what the code does.
openam-documentation/openam-doc-source/src/main/asciidoc/install-guide/chap-install-tools.adoc:151, openam-shared/src/main/java/com/sun/identity/security/keystore/AMX509TrustManager.java:79-81, :123-127, openam-core/src/main/java/com/sun/identity/protocol/https/Https.java:48-50
AMX509TrustManager reads the same property. When it is true, checkServerTrusted returns before any chain validation. Https's static initializer installs that trust manager (through SSLSocketFactoryManager.getSocketFactory()) together with AMHostnameVerifier, so wherever the property has any effect it accepts any server certificate. reference/chap-config-ref.adoc:5428-5429 already documents it that way ("trust whatever certificate is presented without checking"). Removing the NOTE is still right: the stock ssoadm script sets no java.protocol.handler.pkgs, so the property does nothing there. Only the stated reason is wrong, and with a squash merge it would end up in the commit message describing a trust-all switch as harmless. Suggested wording for that bullet:
The `ssoadm` "trust all certificates" note is removed rather than rewritten: its KB link is dead, and
`com.iplanet.am.jssproxy.trustAllServerCerts` disables both certificate-chain validation
(AMX509TrustManager) and host name verification (AMHostnameVerifier) only when the
`com.sun.identity.protocol` handler is installed, which the stock `ssoadm` script does not do.
The step above already documents the correct `javax.net.ssl.trustStore` option.
|
The reason given in the description was wrong. When The commit message never made this claim, so the branch is unchanged. |
Fixes #1155
Smaller defects in the OpenAM guides, as rendered on https://doc.openidentityplatform.org.
Changes
link:hhttps://…→link:https://…inadmin-guide/chap-mobile.adoc.{openam-version}shown literally —subs="attributes+"added to the three console blocks that render the placeholder on the live site (install-guide/chap-install-tools.adoc×2,dev-guide/chap-client-dev.adoc). A scan of every verbatim block in the guides found no others; theunzipblock at line 260 already hadsubs="attributes".getting-started/chap-first-steps.adocwas never closed, so it swallowed the rest of the chapter: the live page shows<p>=== Trying It Out</p>instead of a heading. Closed with====.*markers (leftovers of bold formatting) that were rendered in front of five examples inadmin-guide/chap-usr-selfservices.adoc, and put the%link%email bodies there and inreference/chap-config-ref.adocinto literal monospace (`+…+`).backstage.forgerock.com/forgerock.orgare gone:a47487197, ×5) → theopenam-samplesdirectory of this repository; the STS sample path indev-guide/chap-sts.adocnow matches it (openam-source/openam-samples/sts-example-code);a97304600) → ACI: Disable Anonymous Access in the OpenDJ Administration Guide;security_advisory1/2, the internal javadoc ondownload.forgerock.org).ssoadm"trust all certificates" note is removed rather than rewritten: its KB link is dead, andcom.iplanet.am.jssproxy.trustAllServerCertsdisables both certificate-chain validation (AMX509TrustManager) and host name verification (AMHostnameVerifier) only when thecom.sun.identity.protocolhandler is installed (throughjava.protocol.handler.pkgsoropensso.protocol.handler.pkgs), which neither the stockssoadmscript nor the default configuration does. The step above it already documents the correctjavax.net.ssl.trustStoreoption.Notes
%link%was not actually rendered as a link: both the live site and a local render show it as escaped text inside<code>, with no<a href="%link%">element. The 404 most likely came from a checker that extractshref="…"from page text. The visible defect there was the stray*.http://forgerock.comin the SAMLRelayStateexamples ofadmin-guide/chap-federation.adocandwww.forgerock.orgin the scripting examples are sample values, not links, and are left as they are.reference/chap-config-ref.adocstill says "Use the ForgeRock Backstage website to provision values for the following Simple Notification Service properties". It is not a link, and how Open Identity Platform users obtain SNS credentials needs a separate decision.Testing
Rendered all 14 changed chapters with Asciidoctor.js, both from
origin/masterand from this branch:chap-first-steps.adoc: unterminated example blockis gone;{openam-version}left (the three blocks show16.1.4), nohhttps, "Trying It Out" is an<h3>, no stray*before the examples, and 16 → 0hrefs toforgerock.com/forgerock.org.The full Antora build was not run locally.