[midPoint] entitlement-management-issues

Ostrovsky, Matias mostrovsky at deloitte.com
Fri Jun 19 17:24:22 CEST 2020


Hello,

My team is having trouble while managing entitlements. We think the issue is from midPoint code, not the connector.
The following images describe how we proceed to add and remove entitlement objects to a role:


We go to a role (named rol_test in the example) and then we select the induced entitlement tab
[cid:image007.png at 01D64633.17FCACC0]


Then App A is added with Account,default and ref:group parameters
[cid:image008.png at 01D64633.17FCACC0]


[cid:image009.png at 01D64633.17FCACC0]

Add button is clicked and then we proceed to add Entitlement003 and Entitlement001 entitlements. After this, changes are successfully saved.
[cid:image010.png at 01D64633.17FCACC0]


We go to rol_test again and delete Entitlement001 saving the change.
[cid:image011.png at 01D64633.17FCACC0]

Then the first error appears. Entitlement001 gets duplicated. Error that always happens. We are currently working on 4.0.1 and the error persists in 3.9 and later versions, except for 4.0.
[cid:image012.png at 01D64633.17FCACC0]


The second error comes when adding an entitlement with the same name, for example Entitlement003. We add it, the screen is the same as above, so it seems that there are no changes,
But Entitlement001 is now duplicated again. Error that persists on 3.9 and later versions.
[cid:image013.png at 01D64633.17FCACC0]




So, here we have two errors. Duplicated entitlement when trying to remove it and same name entitlement addition allowed, duplicating another one (sometimes the same). My question is...
Do we proceed incorrectly or midpoint code is failing? Is there an existing code to fix this? I hope that you can help us, thank you for your time.


Regards,

--
Matias Ostrovsky
Consultant | Cyber Risk Services | Risk Advisory
Deloitte & Co. S.A.
Av. Caseros 3563, 5° piso, C1263AAE, Buenos Aires, Argentina
Tel.: +54 (11) 4390 2600 Int: 2854
mostrovsky at deloitte.com<mailto:mostrovsky at deloitte.com> | http://www.deloitte.com/ar
--

[cid:image001.png at 01D59324.E9012610]

[cid:image002.png at 01D59324.E9012610]<https://www.facebook.com/YourFutureatDeloitteArgentina/>[cid:image003.png at 01D59324.E9012610]<https://www.linkedin.com/company/deloitte-argentina> [cid:image004.png at 01D59324.E9012610] <https://twitter.com/deloittearg>  [cid:image005.png at 01D59324.E9012610] <https://www.youtube.com/user/DeloitteArgentina>  [cid:image006.png at 01D59324.E9012610] <https://www.instagram.com/deloitte_ar/>
--
Antes de imprimir, piensa en tu responsabilidad con el medio ambiente.


Deloitte refers to a Deloitte member firm, one of its related entities, or Deloitte Touche Tohmatsu Limited ("DTTL"). Each Deloitte member firm is a separate legal entity and a member of DTTL. DTTL does not provide services to clients. Please see www.deloitte.com/about to learn more.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.png
Type: image/png
Size: 1421 bytes
Desc: image001.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.png
Type: image/png
Size: 1363 bytes
Desc: image002.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0001.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image003.png
Type: image/png
Size: 1416 bytes
Desc: image003.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0002.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image004.png
Type: image/png
Size: 1398 bytes
Desc: image004.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0003.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image005.png
Type: image/png
Size: 1308 bytes
Desc: image005.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image006.png
Type: image/png
Size: 1190 bytes
Desc: image006.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0005.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image007.png
Type: image/png
Size: 18455 bytes
Desc: image007.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0006.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image008.png
Type: image/png
Size: 15040 bytes
Desc: image008.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0007.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image009.png
Type: image/png
Size: 17490 bytes
Desc: image009.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0008.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image010.png
Type: image/png
Size: 20174 bytes
Desc: image010.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0009.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image011.png
Type: image/png
Size: 21541 bytes
Desc: image011.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0010.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image012.png
Type: image/png
Size: 22868 bytes
Desc: image012.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0011.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image013.png
Type: image/png
Size: 24999 bytes
Desc: image013.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200619/e465b3a2/attachment-0012.png>


More information about the midPoint mailing list