Uploaded image for project: 'Grouper'
  1. Grouper
  2. GRP-5448

User with read/update and provisioner admin privs can set provisioning but not remove it

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Minor
    • 4.14.2, 5.11.3
    • 4.12.0
    • provisioning, UI
    • None

    Description

      A non-wheel user has read/update on a group, and also is in the admin group for a provisioner. They can set Provision To, but can't unset it, getting error "Error: Cannot access provisioning., Problem calling method removeProvisioningOnGroup".

      grouper_1    | grouper;grouper_error.log;dev;nothing;2024-05-22T19:27:28,808: [http-nio-0.0.0.0-8080-exec-1] ERROR GrouperUiRestServlet.doGet(372) - [] - Problem calling reflection from URL: edu.internet2.middleware.grouper.grouperUi.serviceLogic.UiV2Provisioning.removeProvisioningOnGroup
      grouper_1    | 
      grouper_1    | java.lang.RuntimeException: Cannot access provisioning.,
      grouper_1    | Problem calling method removeProvisioningOnGroup on edu.internet2.middleware.grouper.grouperUi.serviceLogic.UiV2Provisioning
      grouper_1    | 	at edu.internet2.middleware.grouper.grouperUi.serviceLogic.UiV2Provisioning.removeProvisioningOnGroup(UiV2Provisioning.java:1606)
      grouper_1    | 	at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
      grouper_1    | 	at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:77)
      grouper_1    | 	at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
      grouper_1    | 	at java.base/java.lang.reflect.Method.invoke(Method.java:568)
      grouper_1    | 	at edu.internet2.middleware.grouper.util.GrouperUtil.invokeMethod(GrouperUtil.java:5785)
      grouper_1    | 	at edu.internet2.middleware.grouper.util.GrouperUtil.callMethod(GrouperUtil.java:5736)
      grouper_1    | 	at edu.internet2.middleware.grouper.j2ee.GrouperUiRestServlet.doGet(GrouperUiRestServlet.java:336)
      grouper_1    | 	at edu.internet2.middleware.grouper.j2ee.GrouperUiRestServlet.doPost(GrouperUiRestServlet.java:204)
      grouper_1    | 	at javax.servlet.http.HttpServlet.service(HttpServlet.java:515)
      grouper_1    | 	at javax.servlet.http.HttpServlet.service(HttpServlet.java:583)
      grouper_1    | 	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:212)
      grouper_1    | 	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:156)
      grouper_1    | 	at org.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:51)
      grouper_1    | 	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:181)
      grouper_1    | 	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:156)
      grouper_1    | 	at org.owasp.csrfguard.CsrfGuardFilter.handleSession(CsrfGuardFilter.java:101)
      grouper_1    | 	at org.owasp.csrfguard.CsrfGuardFilter.doFilter(CsrfGuardFilter.java:91)
      grouper_1    | 	at org.owasp.csrfguard.CsrfGuardFilter.doFilter(CsrfGuardFilter.java:63)
      grouper_1    | 	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:181)
      grouper_1    | 	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:156)
      grouper_1    | 	at edu.internet2.middleware.grouper.ui.GrouperUiFilter.doFilter(GrouperUiFilter.java:1327)
      grouper_1    | 	at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:181)
      grouper_1    | 	at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:156)
      grouper_1    | 	at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:168)
      grouper_1    | 	at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:90)
      grouper_1    | 	at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:483)
      grouper_1    | 	at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:130)
      grouper_1    | 	at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:93)
      grouper_1    | 	at org.apache.catalina.valves.rewrite.RewriteValve.invoke(RewriteValve.java:562)
      grouper_1    | 	at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:74)
      grouper_1    | 	at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:346)
      grouper_1    | 	at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:617)
      grouper_1    | 	at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:63)
      grouper_1    | 	at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:934)
      grouper_1    | 	at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1698)
      grouper_1    | 	at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:52)
      grouper_1    | 	at org.apache.tomcat.util.threads.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1191)
      grouper_1    | 	at org.apache.tomcat.util.threads.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:659)
      grouper_1    | 	at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:63)
      grouper_1    | 	at java.base/java.lang.Thread.run(Thread.java:840)
      

      Attachments

        Activity

          People

            shilen.patel@at.internet2.edu Shilen Patel (duke.edu)
            chad.redman.3@at.internet2.edu Chad Redman (unicon.net)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: