Re: Bloomberg EZproxy stanza
Christopher D Vidas <[email protected]>
| Newsgroups | gmane.education.ezproxy |
|---|---|
| Message-ID | <SN4PR0601MB3632E43CA25EDB8157C3AEB6DF8F0@SN4PR0601MB3632.namprd06.prod.outlook.com> |
Robert, After following past conversations about Bloomberg Tax and struggling with the obstacles that resulted from them no longer supporting EZproxy, we decided to play along with the access model they were seemingly forcing us to use. The positive aspect of that decision is that we no longer encounter various unexpected errors, but the much larger problem is that we now have to relay student rosters to the vendor to set up username and password access, as your message below suggested. In addition, apparently we haven't had a sales rep assigned to our region in months, so we can't even communicate our frustrations to anyone specific. Of course, I'll add my voice to yours and others once we are assigned a sales rep, and hopefully they'll take our concerns seriously to help restore seamless access again. Chris Christopher D. Vidas Electronic Resources Librarian Clemson University Library Depot 103 Clemson Research Blvd Anderson, SC 29625 864-656-5175 [email protected]<mailto:[email protected]> From: EZproxy List <[email protected]> On Behalf Of Robert Heaton Sent: Tuesday, September 17, 2019 3:29 PM To: [email protected] Subject: [EZPROXY-L] Bloomberg EZproxy stanza To the EZproxy list plus individuals who have posted questions about this in the past: **TL;DR: I don't have a solution to the Bloomberg proxy problem, but I think I understand what the problem is.** When attempting to use EZproxy for our Bloomberg Tax & Accounting subscription (at https://www.bloomberglaw.com/product/tax/page/page_federal), we have experienced various errors. Most commonly, users arrive at the landing page and can browse to resources, but using the search box at any time redirects users back to the landing page. We have tried changing our stanza in different ways but without success. In troubleshooting this month, we received an email from [email protected]<mailto:[email protected]> that stated, "As of January 2019, we no longer support EZProxy." Follow-up with another support person resulted in this message: "Off campus access depends on the contract. Usually schools are given a set number of seats to register users for a username and password. You may want to contact your account rep and they should be able to provide more info for off campus access." Accordingly, I looked at our latest contract and saw that they agree to give us IP-authenticated access (for a set number of users), but there is no mention of off-campus access or EZproxy. An email from a year ago may explain what's going on on their end. Based on this information, we were able to fix the problem we were having in summer 2018, but their subsequent updates to the platform seem to have brought it back. Here is that response verbatim: At the bottom of the SAML (Validating Credentials - look at the source) Response HTML POST payload, you will see: <BR> <input type="hidden" size=50 name="TARGET" value="https://www-bloomberglaw-com.dist.lib.usu.edu/product/tax/page/page_federal"><BR> <input type="hidden" size=50 name="RelayState" value="https://www-bloomberglaw-com.dist.lib.usu.edu/saml/acs"><BR> </form> </body> It appears that when this POST traverses through EZProxy that EZProxy is not changing the TARGET to the appropriate value. Which is (you will not see this in your browser but the PRODUCT will get this as the (correct) TARGET value): <input type="hidden" size=50 name="TARGET" value="https://www.bloomberglaw.com/product/tax/page/page_federal"><BR> What is happening is that the PRODUCT (BTAX) is logging in the USER correctly but assumes that someone is trying to redirect the USER to a URL that is not in the approved list of TARGETS. When this happens, BTAX (or BLAW for that matter) will attempt to redirect the user to: http://www.bloomberglaw.com/start Based on this information, we tried addressing this problem by adding these lines to our stanza: Find name="RelayState" value="https:// Replace name="RelayState" value="https://^A Find name='RelayState' value='https:// Replace name='RelayState' value='https://^A Find name="TARGET" value="https:// Replace name="TARGET" value="https://^A That makes it so that the URL https://www-bloomberglaw-com.dist.lib.usu.edu/saml/acs never gets passed back to them, in favor of the actual page the user is on. However, the problem remains: the URL that we pass back to them is not on their list of approved targets, so it just drops the user back at a page that is on that list. As far as I understand it, what they're saying is that they want our server to send them the URL https://www.bloomberglaw.com/product/tax/page/page_federal instead of https://www-bloomberglaw-com.dist.lib.usu.edu/product/tax/page/page_federal. There is no way for EZproxy to work without rewriting the URL, so the only option is for them to make changes to their configuration to accept requests in this format. The above message also makes it clear that they are expecting SAML authentication instead of EZproxy, and it was gratifying(?) to have them acknowledge later that they do not support EZproxy. This resource does work through our VPN, so if that's an option, it may work for you as well. Still, I know we will be putting considerable pressure on our sales rep leading up to the renewal to lobby for EZproxy support. If anyone has ideas for getting the message across, I would love to hear them. Thanks and good luck! Robert Heaton Collection Management Librarian Utah State University Libraries ________________________________ To unsubscribe from the EZPROXY-L list, click the following link: http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1 ******************************************************************** If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences, you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>. Or email [email protected] including the relevant text below in the body of the email: • To unsubscribe: "unsubscribe EZPROXY-L" • To receive EZPROXY-L in digest form: "set EZPROXY-L digest" • To set your options to no mail: "set EZPROXY-L nomail" • To receive these messages in the future "set EZPROXY-L mail" To contact the list owners directly please send your message to [email protected]. If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum. To unsubscribe from all OCLC marketing email communications (including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters), please email us at [email protected].