https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=43695 Bug ID: 43695 Summary: ISO 18626 agency identifiers are hardcoded to sup_agency_value / req_agency_value Initiative type: --- Sponsorship --- status: Product: Koha Version: Main Hardware: All OS: All Status: NEW Severity: major Priority: P5 - low Component: ILL Assignee: koha-bugs@lists.koha-community.org Reporter: minhpq@tinhvan.com QA Contact: testopia@bugs.koha-community.org CC: lisette@bywatersolutions.com, pedro.amorim@openfifth.co.uk, tomascohen@gmail.com Target Milestone: --- Split out of bug 43674 comment #2 at Pedro Amorim's request. Koha/ILL/ISO18626/Request.pm builds the supplyingAgencyMessage payload with both agency identifiers hardcoded: agencyIdValue => 'sup_agency_value', # line 352 agencyIdValue => 'req_agency_value', # line 359 Impact The requesting agency cannot tell which library the message came from. Testing against a third-party implementation, every supplyingAgencyMessage from Koha arrived with supplyingAgencyId = "sup_agency_value" which matches no configured partner, so there is no way to verify the sender. This matters more for supplyingAgencyMessage than for the other message types. ISO 18626 puts requestingAgencyAuthentication in request and requestingAgencyMessage, but has no equivalent element for supplyingAgencyMessage — the agency identifier is the only thing in that message that says who sent it. With it hardcoded, a receiver has two options, both bad: trust any sender, or fall back to matching the transaction on requestingAgencyRequestId alone, which is what we had to do. Suggested fix The supplying agency identifier is the library's own, so it belongs in configuration — one value per Koha instance rather than per partner. The requesting agency identifier is already known per partner: bug 37762 stores each requesting agency in iso18626_requesting_agencies, which has a `type` column (DNUCNI/ICOLC/ISIL) but no identifier value column, so that would need one too. Note the same defect exists in the out-of-tree plugin, reported separately at https://github.com/openfifth/koha-ill-iso18626/issues/8 with a patch at https://github.com/openfifth/koha-ill-iso18626/pull/5. The approach taken there was: `requesting_agency_id` / `requesting_agency_id_type` for the library itself, and `agency_id` / `agency_id_type` per partner. Core may well want something different given it already has iso18626_requesting_agencies, but the shape of the problem is the same. How it was found Interoperability testing between Koha 26.05.02 and a third-party ISO 18626 implementation generated from the official v1.2 XSD. Related: bug 43674 (envelope, patched), bug 43694 (element order), bug 37762 (where the supplying side was added). Happy to test a patch for this against the same setup. -- You are receiving this mail because: You are watching all bug changes. You are the assignee for the bug.