grouper-users - RE: [grouper-users] restricting subject results in ui search
Subject: Grouper Users - Open Discussion List
List archive
- From: "Hyzer, Chris" <>
- To: Derek D Owens <>, "" <>
- Subject: RE: [grouper-users] restricting subject results in ui search
- Date: Wed, 9 Nov 2016 20:53:41 +0000
- Accept-language: en-US
- Authentication-results: spf=none (sender IP is ) ;
- Ironport-phdr: 9a23:tQpeux8ITmiJ0f9uRHKM819IXTAuvvDOBiVQ1KB21OocTK2v8tzYMVDF4r011RmSDN6ds6oP0rOO+4nbGkU4qa6bt34DdJEeHzQksu4x2zIaPcieFEfgJ+TrZSFpVO5LVVti4m3peRMNQJW2aFLduGC94iAPERvjKwV1Ov71GonPhMiryuy+4ZPebgFGiTanfb9+MBq6oRjMusUKnIBvNrs/xhzVr3VSZu9Y33loJVWdnxb94se/4ptu+DlOtvwi6sBNT7z0c7w3QrJEAjsmNXs15NDwuhnYUQSP/HocXX4InRdOHgPI8Qv1Xpb1siv9q+p9xCyXNtD4QLwoRTiv6bpgRQT2gykbKTE27GDXitRxjK1FphKhuwd/yJPQbI2MKfZyYr/RcdYcSGFcXMheSjZBD5u8YYUREuQBIehWoYrzp1QMrBuxGQajCfj1xTNUmnP7x7E23/gjHAzAwQcuH8gOsHPRrNjtOqscU+C0zajWwjXZd/9dxCnw6IjSchAguvGAU697fM3UyUYzFwPEjlSRppL/Pz6O1+QNqHSU4/B9VeK3lWEnrQdxriKxycgxl4nEn4QYwU3H+yVh2Is5O8e3RFJmbdOhDZdcqjyWOo54Qs4tX21kpCM3x78YtpO0YCQHzZEqywDDZ/GFa4SE/xzuWPqLLTp8mX5pYqyziwu2/ES61+HxVMi53VBXpSRfiNbMrGoC1xnL58iHVPR9+kCh1C6X2Q3P7e9IPV04mbPGJZA537I8j50Tvl/dESPsn0X2kbOWeV4j+ui17eTof6/qpoeGN49zlgHxLLghmtC+AeQ/NAgCRW+b+fmg1L3n+k35R7ZKgucqnanetZDWPcUbpqinDA9Jyosv9QywAyu73NkdgHULMU9JdReJj4XmJ13CPPX1APWhjFmjjDtmwvXLMqP9DpjPNnTDla3ufbd5605S0gozytVf6opRCr4dIPLyWk7wu8LCDhIiMgy02ProBM9g1oMGR22PBKmZPLnMvlCV++IjO/OMa5MNuDbhN/gl4ObjjXAjmV8aYKmpxYUYaGqhEvR7OEWWf2DsgswaHGcOvwo+V/DqiEacXTJJZnayWb486S8hCIKgE4jDWp6hjKaf0yimA50FLlxBX3yBC3rrP6nMfOgBbjnadsNmjTECTpCnR8ks2Qz48EewxKBgM/LZ4GgFrp/5z/B04fHejxc/6WYyAsiAmSnZQHtzg3sFXXorx61lumR8zEuOy651n6YeGNBOsaBnSAA/YNT83v53EZS6cQLbf8zDAAKjSdW3EzwrZtMqyJkTe0t7HZOvgg2VjHniOKMci7HeXM98yanbxXWkYp8lk3s=
- Spamdiagnosticmetadata: NSPM
- Spamdiagnosticoutput: 1:99
Can you not let users search but if someone knows the exact ID it would look them up? I think your way would work though you would have unresolvables in the UI… which I think could be bad. Can the other view return them by ID but not by identifier or search and maybe obfuscate the data (similar to above)? We could try to make a generic subject customizer based on configured cols in the JDBC2 source if you like… should be easy… Thanks Chris From: [mailto:]
On Behalf Of Derek D Owens In our Grouper 2.3.0 system, we're using a Db view via GrouperJdbcSourceAdapter2 for subjects. The subjects in our Db contain many different types of user NetIDs, including ones used for administrative (privileged) access. Due to concerns
about information exposure, it's been requested that we restrict access to these privileged accounts within the Grouper UI so that they do not return in search results for end-users of the UI. We do need to have these subjects available to place into groups,
so they need to be available and resolvable in our subject Db. I'm investing writing a SubjectCustomizer with filterSubjects to filter out the search results in the UI. However, would a viable quick fix be to create a new subject view in our subjects Db which does not return the privileged subjects
and configure our Grouper UI instance to use it? We'd keep our grouper daemon (etc.) configured to the use the full subject Db view. Would there be any issues caused by the Grouper UI using a different subject Db than the other grouper components? Could this
affect the membership data in the grouper Db for those privileged subjects? Thanks!
|
- [grouper-users] restricting subject results in ui search, Derek D Owens, 11/09/2016
- RE: [grouper-users] restricting subject results in ui search, Hyzer, Chris, 11/09/2016
Archive powered by MHonArc 2.6.19.