https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=43674 --- Comment #5 from Pedro Amorim (ammopt) <pedro.amorim@openfifth.co.uk> --- Hi Phan, I've submitted patches here for the envelope issue. I've taken note of bug 43694 and plan to look into it. Again, thank you for your testing and feedback. Please open a new bug for this: (In reply to Phan Quang Minh from comment #2)
1. Agency identifiers are hardcoded in core too
Koha/ILL/ISO18626/Request.pm, in the supplyingAgencyMessage payload:
agencyIdValue => 'sup_agency_value', # line 352 agencyIdValue => 'req_agency_value', # line 359
This is the same defect reported against the plugin at https://github.com/openfifth/koha-ill-iso18626/issues/8, but here it is in core, on the supplying side added by bug 37762.
The consequence on the receiving end is concrete: the requesting agency cannot tell which library the message came from. In our case the message arrived with supplyingAgencyId = "sup_agency_value", which matches no configured partner, so there is no way to verify the sender. That matters more for supplyingAgencyMessage than for other message types, because ISO 18626 puts requestingAgencyAuthentication in request and requestingAgencyMessage but has no equivalent element for supplyingAgencyMessage — the agency identifier is the only thing in the message that says who sent it.
The identifier presumably wants to come from the library's own configuration, alongside whatever bug 37762 already stores per requesting agency in iso18626_requesting_agencies.
-- You are receiving this mail because: You are watching all bug changes. You are the assignee for the bug.