Skip to Content.
Sympa Menu

grouper-users - RE: [grouper-users] restricting subject results in ui search

Subject: Grouper Users - Open Discussion List

List archive

RE: [grouper-users] restricting subject results in ui search


Chronological Thread 
  • From: "Hyzer, Chris" <>
  • To: Derek D Owens <>, "" <>
  • Subject: RE: [grouper-users] restricting subject results in ui search
  • Date: Wed, 9 Nov 2016 20:53:41 +0000
  • Accept-language: en-US
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:tQpeux8ITmiJ0f9uRHKM819IXTAuvvDOBiVQ1KB21OocTK2v8tzYMVDF4r011RmSDN6ds6oP0rOO+4nbGkU4qa6bt34DdJEeHzQksu4x2zIaPcieFEfgJ+TrZSFpVO5LVVti4m3peRMNQJW2aFLduGC94iAPERvjKwV1Ov71GonPhMiryuy+4ZPebgFGiTanfb9+MBq6oRjMusUKnIBvNrs/xhzVr3VSZu9Y33loJVWdnxb94se/4ptu+DlOtvwi6sBNT7z0c7w3QrJEAjsmNXs15NDwuhnYUQSP/HocXX4InRdOHgPI8Qv1Xpb1siv9q+p9xCyXNtD4QLwoRTiv6bpgRQT2gykbKTE27GDXitRxjK1FphKhuwd/yJPQbI2MKfZyYr/RcdYcSGFcXMheSjZBD5u8YYUREuQBIehWoYrzp1QMrBuxGQajCfj1xTNUmnP7x7E23/gjHAzAwQcuH8gOsHPRrNjtOqscU+C0zajWwjXZd/9dxCnw6IjSchAguvGAU697fM3UyUYzFwPEjlSRppL/Pz6O1+QNqHSU4/B9VeK3lWEnrQdxriKxycgxl4nEn4QYwU3H+yVh2Is5O8e3RFJmbdOhDZdcqjyWOo54Qs4tX21kpCM3x78YtpO0YCQHzZEqywDDZ/GFa4SE/xzuWPqLLTp8mX5pYqyziwu2/ES61+HxVMi53VBXpSRfiNbMrGoC1xnL58iHVPR9+kCh1C6X2Q3P7e9IPV04mbPGJZA537I8j50Tvl/dESPsn0X2kbOWeV4j+ui17eTof6/qpoeGN49zlgHxLLghmtC+AeQ/NAgCRW+b+fmg1L3n+k35R7ZKgucqnanetZDWPcUbpqinDA9Jyosv9QywAyu73NkdgHULMU9JdReJj4XmJ13CPPX1APWhjFmjjDtmwvXLMqP9DpjPNnTDla3ufbd5605S0gozytVf6opRCr4dIPLyWk7wu8LCDhIiMgy02ProBM9g1oMGR22PBKmZPLnMvlCV++IjO/OMa5MNuDbhN/gl4ObjjXAjmV8aYKmpxYUYaGqhEvR7OEWWf2DsgswaHGcOvwo+V/DqiEacXTJJZnayWb486S8hCIKgE4jDWp6hjKaf0yimA50FLlxBX3yBC3rrP6nMfOgBbjnadsNmjTECTpCnR8ks2Qz48EewxKBgM/LZ4GgFrp/5z/B04fHejxc/6WYyAsiAmSnZQHtzg3sFXXorx61lumR8zEuOy651n6YeGNBOsaBnSAA/YNT83v53EZS6cQLbf8zDAAKjSdW3EzwrZtMqyJkTe0t7HZOvgg2VjHniOKMci7HeXM98yanbxXWkYp8lk3s=
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

Can you not let users search but if someone knows the exact ID it would look them up?

 

I think your way would work though you would have unresolvables in the UI…  which I think could be bad.

 

Can the other view return them by ID but not by identifier or search and maybe obfuscate the data (similar to above)?

 

We could try to make a generic subject customizer based on configured cols in the JDBC2 source if you like… should be easy…

 

Thanks

Chris

 

 

From: [mailto:] On Behalf Of Derek D Owens
Sent: Wednesday, November 09, 2016 2:10 PM
To:
Subject: [grouper-users] restricting subject results in ui search

 

In our Grouper 2.3.0 system, we're using a Db view via GrouperJdbcSourceAdapter2 for subjects. The subjects in our Db contain many different types of user NetIDs, including ones used for administrative (privileged) access. Due to concerns about information exposure, it's been requested that we restrict access to these privileged accounts within the Grouper UI so that they do not return in search results for end-users of the UI.  We do need to have these subjects available to place into groups, so they need to be available and resolvable in our subject Db. 

 

I'm investing writing a SubjectCustomizer with filterSubjects to filter out the search results in the UI. However, would a viable quick fix be to create a new subject view in our subjects Db which does not return the privileged subjects and configure our Grouper UI instance to use it? We'd keep our grouper daemon (etc.) configured to the use the full subject Db view. Would there be any issues caused by the Grouper UI using a different subject Db than the other grouper components? Could this affect the membership data in the grouper Db for those privileged subjects?

 

Thanks!

 


Regards,
Derek




Archive powered by MHonArc 2.6.19.

Top of Page