SAP Knowledge Base Article - Preview

3787033 - odata service returns saml login page or shows 'no user' when called via integration/proxy; bearer token missing or icf handler not oauth-capable

Symptom

  • The OData service runs successfully in the Gateway Client and returns the expected JSON payload.
  • When called via an integration flow or API gateway/proxy, the subsequent OData GET arrives as User = and a SAML IdP selection page is presented instead of JSON.
  • Access through the proxy returns a SAML login page instead of the expected payload.
  • Error messages observed: "No OAuth 2.0 applicable ICF handler registered", "scope_check_impossible".


Read more...

Environment

  • Framework: SAP Gateway (OData) on AS ABAP with SAML 2.0 and OAuth 2.0 (SAML Bearer) authentication
  • Framework: OAuth 2.0 Server in AS ABAP; transactions used include SICF, /IWFND/MAINT_SERVICE, SAML2, SMICM, SEC_TRACE_ANALYZER

Keywords

odata, saml login page, user = no user, bearer token missing, authorization header, oauth 2.0, saml bearer assertion, icf handler, /IWFND/CL_SODATA_HTTP_HNDL_OAT, /IWFND/CL_SODATA_HTTP_HANDLER, sap gateway, sicf, /IWFND/MAINT_SERVICE, sec_trace_analyzer, redirect to saml , KBA , OPU-GW-COR , Framework , BC-SEC-LGN-OA2 , OAuth 2.0 for ABAP , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.