Wednesday, August 13, 2014

Trace components

Trace components

There are three main trace components.

WebSphere Commerce

The following are the tracing components in WebSphere Commerce:
Tracing Component WebSphere JRAS Extensions Trace Logger
ACCESSCONTROL (access control) com.ibm.websphere.commerce.WC_ACCESSCONTROL
APPROVAL (approvals) com.ibm.websphere.commerce.WC_APPROVAL
ATTACHMENT (managed files) com.ibm.websphere.commerce.WC_ATTACHMENT
BI (business intelligence) com.ibm.websphere.commerce.WC_BI
BUSINESSCONTEXT (business context service) com.ibm.websphere.commerce.WC_BUSINESSCONTEXT
CACHE (caching) com.ibm.websphere.commerce.WC_CACHE
CALCULATION com.ibm.websphere.commerce.WC_CALCULATION
CATALOG (catalog) com.ibm.websphere.commerce.WC_CATALOG
CATALOGTOOL (catalog tooling within the WebSphere Commerce Accelerator) com.ibm.websphere.commerce.WC_CATALOGTOOL
CF (command framework) com.ibm.websphere.commerce.WC_CF
COLLABORATION (collaborative workspaces) com.ibm.websphere.commerce.WC_COLLABORATION
COMMAND (commands) com.ibm.websphere.commerce.WC_COMMAND
CONTENT (content management) com.ibm.websphere.commerce.WC_CONTENT
CONTRACT (business agreements and contracts) com.ibm.websphere.commerce.WC_CONTRACT
CURRENCY (currency) com.ibm.websphere.commerce.WC_CURRENCY
DATASOURCE (data source) com.ibm.websphere.commerce.WC_DATASOURCE
DB (database schema) com.ibm.websphere.commerce.WC_DB
DEVTOOLS (WebSphere Commerce development environment tooling) com.ibm.websphere.commerce.WC_DEVTOOLS
EDP (event-driven payments) com.ibm.websphere.commerce.WC_EDP
EJB (enterprise beans) com.ibm.websphere.commerce.WC_EJB
EVENT (WebSphere Commerce events, such as user traffic or business auditing) com.ibm.websphere.commerce.WC_EVENT
EXCHANGE (exchange) com.ibm.websphere.commerce.WC_EXCHANGE
 foundation.client com.ibm.commerce.foundation.client
 foundation.server com.ibm.commerce.foundation.server.command.bod
INVENTORY (inventory) com.ibm.websphere.commerce.WC_INVENTORY
LOADER (massload utility) com.ibm.websphere.commerce.WC_LOADER
LOBTOOLS (Management Center line of business tools) com.ibm.commerce.lobtools
LOBTOOLS.FOUNDATION.MODEL (the Management Center foundation subcomponent, model) com.ibm.commerce.lobtools.foundation.model
LOBTOOLS.FOUNDATION.MODEL (the Management Center foundation subcomponent, service) com.ibm.commerce.lobtools.foundation.service
LOBTOOLS.FOUNDATION.MODEL (the Management Center foundation subcomponent, util) com.ibm.commerce.lobtools.foundation.util
LOBTOOLS.FOUNDATION.MODEL (the Management Center foundation subcomponent, view) com.ibm.commerce.lobtools.foundation.view
MARKETING (marketing) com.ibm.websphere.commerce.WC_MARKETING
MASSEXTRACT (massextract utility) com.ibm.websphere.commerce.WC_MASSEXTRACT
MASSLOAD (massload utility) com.ibm.websphere.commerce.WC_MASSLOAD
MERCHANDISING (merchandising) com.ibm.websphere.commerce.WC_MERCHANDISING
MESSAGING (messaging) com.ibm.websphere.commerce.WC_MESSAGING
METAPHOR (Product Advisor shopping metaphors) com.ibm.websphere.commerce.WC_METAPHOR
NEGOTIATION (negotiations and auctions) com.ibm.websphere.commerce.WC_NEGOTIATION
ORDER (orders) com.ibm.websphere.commerce.WC_ORDER
PERFMONITOR (performance monitor) com.ibm.websphere.commerce.WC_PERFMONITOR
COMPONENT_PORTAL com.ibm.websphere.commerce.WC_PORTAL
PPC (Payment Plug-in Controller) com.ibm.websphere.commerce.WC_PPC
PPC_LOCPLUGIN (Line of credit payment plug-in) com.ibm.websphere.commerce.WC_PPC_LOCPLUGIN
6.0.0.2 PPC_PAYMENTECH_PLUGIN com.ibm.websphere.commerce.WC_PPC_PAYMENTECHPLUGIN
PPC_PLUGIN (payment plug-in specification) com.ibm.websphere.commerce.WC_PPC_PLUGIN
PPC_SIMPLEOFFLINE (SimpleOffline payment plug-in) com.ibm.websphere.commerce.WC_PPC_SIMPLEOFFLINE
PPC_WCPPLUGIN (WC Payments payment plug-in) com.ibm.websphere.commerce.WC_PPC_WCPPLUGIN
PVC (pervasive computing) com.ibm.websphere.commerce.WC_PVC
RAS (logging) com.ibm.websphere.commerce.WC_RAS
REPORTING (reporting) com.ibm.websphere.commerce.WC_REPORTING
RFQ (Requests for Quotes) com.ibm.websphere.commerce.WC_RFQ
RULESSYSTEM (rules-based discounts) com.ibm.websphere.commerce.WC_RULESYSTEM
SCHEDULER com.ibm.websphere.commerce.WC_SCHEDULER
SEARCH (search) com.ibm.websphere.commerce.WC_SEARCH
Note: Use of this tracing component enables you to see the SQL being generated for the search.
COMPONENT_SENSITIVE_INFO com.ibm.websphere.commerce.WC_SENSITIVE_INFO
SEOSITEMAP (Integration with sitemaps) com.ibm.commerce.seo
SERVER (WebSphere Commerce Server or runtime) com.ibm.websphere.commerce.WC_SERVER
COMPONENT_SERVER_MANAGEMENT com.ibm.websphere.commerce.WC_SERVER_MANAGEMENT
SESSIONMANAGEMENT (cookie-based or URL-writing session management) com.ibm.websphere.commerce.WC_SESSIONMANAGEMENT
STOREOPERATIONS (store operations) com.ibm.websphere.commerce.WC_STOREOPERATIONS
TEXTTRANS (txttransfrom utility) com.ibm.websphere.commerce.WC_TEXTTRANS
THREAD (thread) com.ibm.websphere.commerce.WC_THREAD
TICKLER (ticklers) com.ibm.websphere.commerce.WC_TICKLER
TOOLSFRAMEWORK (WebSphere Commerce tools framework for the WebSphere Commerce tooling user interface) com.ibm.websphere.commerce.WC_TOOLSFRAMEWORK
TRANSPORT_ADAPTER (MQSeries adapters) com.ibm.websphere.commerce.WC_TRANSPORT_ADAPTER
UBF (universal business flow for approvals, auctions, contracts, and trading) com.ibm.websphere.commerce.WC_UBF
USER (members) com.ibm.websphere.commerce.WC_USER
UTF (approvals) com.ibm.websphere.commerce.WC_UTF
WC_EXTERN (custom code)
Deprecated
com.ibm.websphere.commerce.WC_EXTERN
Important: Use of this tracing component has been deprecated and only remains for backwards compatibility to aid migration from previous releases of WebSphere Commerce.
Custom code should use the WebSphere Application Server recommended tracing. See the Add logging and tracing to your application topic in the Websphere Application Server Information Center for more information.
WC_GIFTREGISTRY (Gift registry) com.ibm.websphere.commerce.WC_GIFTREGISTRY
WCA_DEBUG (WebSphere Commerce Analyzer debugging) com.ibm.websphere.commerce.WC_WCA_DEBUG
Collects more advanced trace information. By default WCA_DEBUG is turned off. To turn it on, add an entry in the file WCA_installdir/bin/runtimeTraceLog.xml.
WCA_INFO (WebSphere Commerce Analyzer data) com.ibm.websphere.commerce.WC_WCA_INFO Collect basic trace information. By default, WCA_INFO is always turned on.
WORKSPACE (content management workspaces) com.ibm.websphere.commerce.WC_WORKSPACE
WORKSPACETOOL (content management workspace tooling) com.ibm.websphere.commerce.WC_WORKSPACETOOL
XMLTRANS (xmltransform utility) com.ibm.websphere.commerce.WC_XMLTRANS

JCA connectors

The following are the JCA connectors tracing components in WebSphere Commerce:
Tracing Component WebSphere JRAS Extensions Trace Logger
JCA E-mail connector com.ibm.websphere.commerce.jcaemail
JCA File connector com.ibm.websphere.commerce.jcafile
JCA JMS Connector com.ibm.websphere.commerce.jcajms
JCA Sample Connector com.ibm.websphere.commerce.jcasample

WebSphere Commerce Payments

The following are the Commerce Payments tracing components in WebSphere Commerce:
Tracing Component WebSphere JRAS Extensions Trace Logger
* (gives you everything) com.ibm.websphere.commerce.payments.*
MPF (Payments framework) com.ibm.websphere.commerce.payments.MPF
MPFUI (Payments user interface) com.ibm.websphere.commerce.payments.MPFUI
Cassette_name This enables tracing for any IBM or third party cassette. Cassettes shipped with WebSphere Commerce are VisaNet, Paymentech, BankServACH, OfflineCard, and CustomOffline. com.ibm.websphere.commerce.payments. Cassette_name

View BOD messages in toolkit

To view the BOD request/response XML data, the TCP/IP Monitor in WebSphere Commerce Toolkit is used.
Configuration must be made before enabling the monitor.

For example, the BOD data for the Order service:

  1. The {toolkit_install_dir}\xml\config directory contains a set of com.ibm.commerce.* folders, which contain configuration files that specify the binding information of the corresponding service. For example, to monitor the BOD data for the Order service, com.ibm.commerce.order\wc-component-client.xml should be modified where the TCP/IP monitor can catch the XML data by listening on a port .
Replace the following code in the original wc-component-client.xml:
bindingImpl="com.ibm.commerce.foundation.internal.client.services.invocation.impl.LocalEJBInvocationBindingImpl">
<_config:property name="jndiName" value="ejb/com/ibm/commerce/order/facade/server/OrderLocalFacadeHome" />

with the following code:
bindingImpl="com.ibm.commerce.foundation.internal.client.services.invocation.impl.J2SEWebServiceInvocationBindingImpl">
<_config:property name="url" value="http://localhost:81/webapp/wcs/component/order/services/OrderServices" />

The target host machine is localhost.
Port 81 is the port that the TCP/IP monitor will listen on for BOD data.

2. Restart your WAS server.

3. In your toolkit, navigate to Window > Show View > Other...
Select the TCP/IP Monitor view.
(in the RAD6-based toolkit, the TCP/IP Monitor view is located in Debug)

4. With the TCP/IP Monitor open, click the down-arrow icon, located in the top right corner in the view, and select "Properties...".

5. In the opened monitors window, select "Add..."

6. Change the monitoring port to 81 (as previously specified in the configuration file)

7. Type the host name of the host machine or "localhost" if it is the local machine.

8. "Port: " is the port number that the web 2.0 store uses on the host machine.
80 is the default port number for the web 2.0 store running from a toolkit.
8007 is the default port number using runtime.

9. Select HTTP for the communication type.

10. Click OK.

11. Select the new created monitor from the list, and click Start.

When an order service call is invoked as the store is browsed, the request BOD data is shown on the left side of the TCP/IP Monitor view, and the response BOD data is shown on the right side of the view.


Note:
After using the TCP/IP monitor, you should stop the monitor from continuing to listen on the port and undo the changes made to the wc-component-client.xml file.

All about Policy




There are two types of access control, both of which are policy-based: command-level access control and resource-level access control. 

Command-level, also known as role-based, access control uses a broad type of policy. You can specify that all users of a particular role can run certain types of commands. For example, you can specify that users with the Account Representative role can run any command in the AccountRepresentativesCmdResourceGroup resource group. All controller commands must be protected by command-level access control. In addition, any view that can be called directly, or that can be launched by a redirect from another command must be protected by command-level access control. Command-level access control determines whether a user is allowed to run the particular command within the store you have specified. 


Resource-level -access control uses a fine grain policy. If a command-level policy allows a user to run a command, a subsequent resource-level access control policy can be applied to determine if the user can access the resource in question. Resource-level access policies define the relationship a user must have with a resource in order to perform an action on it. For example, a seller administrator might be permitted to perform an administrative task but only on resources that are owned by the organization for which they are a seller administrator.
To summarize, in command-level access control the "resource" is the command itself and the "action" is to run the command within the current store. The access control check determines if the user is permitted to run the command within the current store. In resource-level access control the "resource" is any protectable resource that the command or bean accesses and the "action" is the command itself.
  





Loading Access Control Policy using SQL

Here is a technique which is an alternate to WCS acpload script. The technique uses a set of SQL's to load Access control policy for new Controller commands and Views.


This would be useful for newbies who might think defining xml / acpload is the only option to define access policy for new views/commands, this is much more simpler and faster approach.
and for the purpose of showing you the difference I will document both infocenter approach and direct SQL approach.

Loading a new View Access control Policy


Here is an example from infocenter to create a new custom View 

http://publib.boulder.ibm.com/infocenter/wchelp/v7r0m0/topic/com.ibm.commerce.developer.tutorial.doc/tutorial/ttd12.htm


Custom View Policy

View Policy XML to be loaded using acpload:
 
<?xml version="1.0" encoding="ISO-8859-1" standalone="no" ?>
<!DOCTYPE Policies SYSTEM "../dtd/accesscontrolpolicies.dtd">
<Policies>
<Action Name="MyNewView"
   CommandName="MyNewView">
</Action>
<ActionGroup Name="AllSiteUsersViews"
            OwnerID="RootOrganization">
            <ActionGroupAction Name="MyNewView"/>
</ActionGroup>
</Policies>
You will then copy this xml in /xml/policies and run "acpload" as follows


SQL approach to load VIEW policy:

insert into acaction (acaction_id, action) values ((select counter from keys where tablename='acaction'), 'MyNewView');

insert into acactactgp (ACACTGRP_ID,ACACTION_ID) values
((SELECT ACACTGRP_ID FROM ACACTGRP WHERE GROUPNAME = 'AllSiteUsersViews'
and member_id in (select orgentity_id from orgentity where orgentityname='Root Organization')
),
(select acaction_id from acaction where action='MyNewView'));

UPDATE KEYS SET COUNTER = COUNTER+1 WHERE TABLENAME = 'acaction';


Rollback the Access policy:


delete from acactactgp
  where ACACTION_ID in (select acaction_id from acaction where action='MyNewView')


delete from acaction where action ='MyNewView';



Loading a new Command Access Control Policy
 

Here is an example from infocenter to create a new custom controller command


http://publib.boulder.ibm.com/infocenter/wchelp/v7r0m0/topic/com.ibm.commerce.developer.tutorial.doc/tutorial/ttd13.htm


Access Policy XML:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE import SYSTEM "../../../schema/xml/wcs.dtd">
<import>
<acaction ACACTION_ID="@Execute" ACTION="Execute"/>
<acrescgry ACRESCGRY_ID="@com.ibm.commerce.sample.commands.MyNewControllerCmd" RESCLASSNAME="com.ibm.commerce.sample.commands.MyNewControllerCmd"/>
<acresact ACRESCGRY_ID="@com.ibm.commerce.sample.commands.MyNewControllerCmd" ACACTION_ID="@Execute"/>
<acresgrp ACRESGRP_ID="@AllSiteUserCmdResourceGroup" MEMBER_ID="-2001" GRPNAME="AllSiteUserCmdResourceGroup"/>
<acresgpres ACRESGRP_ID="@AllSiteUserCmdResourceGroup" ACRESCGRY_ID="@com.ibm.commerce.sample.commands.MyNewControllerCmd"/>

</import>
 

SQL approach to load custom command policy

insert into acrescgry
(ACRESCGRY_ID,RESCLASSNAME)
values
((select counter from keys where tablename='acrescgry'),'com.ibm.commerce.sample.commands.MyNewControllerCmd');

insert into acresact
(ACRESCGRY_ID, ACACTION_ID)
values
((select counter from keys where tablename='acrescgry'),(select ACACTION_ID from acaction where action='Execute'));

insert into acresgpres
(ACRESGRP_ID, ACRESCGRY_ID)
values
((select ACRESGRP_ID from acresgrp where MEMBER_ID in
(select orgentity_id from orgentity where orgentityname='Root Organization') and GRPNAME='AllSiteUserCmdResourceGroup'),
(select counter from keys where tablename='acrescgry'));

UPDATE KEYS SET COUNTER = COUNTER+1 WHERE TABLENAME = 'acrescgry';

Rollback the Access policy:
delete from acresgpres where ACRESCGRY_ID in (select ACRESCGRY_ID from acrescgry where  RESCLASSNAME='com.ibm.commerce.sample.commands.MyNewControllerCmd') 

delete from acresact where ACRESCGRY_ID in (select ACRESCGRY_ID from acrescgry where  RESCLASSNAME='com.ibm.commerce.sample.commands.MyNewControllerCmd';

delete from acrescgry where RESCLASSNAME='com.ibm.commerce.sample.commands.MyNewControllerCmd