Skip to Content.
Sympa Menu

grouper-users - RE: [grouper-users] Differencing tool with healing capabilities...

Subject: Grouper Users - Open Discussion List

List archive

RE: [grouper-users] Differencing tool with healing capabilities...

Chronological Thread 
  • From: "Hyzer, Chris" <>
  • To: "Gettes, Michael" <>, Bill Thompson <>
  • Cc: "" <>
  • Subject: RE: [grouper-users] Differencing tool with healing capabilities...
  • Date: Mon, 10 Jul 2017 19:26:27 +0000
  • Accept-language: en-US
  • Authentication-results:; dkim=none (message not signed) header.d=none;; dmarc=none action=none;
  • Ironport-phdr: 9a23:8qr3iR3Q5kAFpyxRsmDT+DRfVm0co7zxezQtwd8ZsegVKPad9pjvdHbS+e9qxAeQG96Eu7QZ06L/iOPJZy8p2d65qncMcZhBBVcuqP49uEgeOvODElDxN/XwbiY3T4xoXV5h+GynYwAOQJ6tL3WbmHC57CYTFxPjLkI1Y72tQs+Bx/iwgqqd9oHPbh4MzB+8arN7IRH85VHeu9UKjJBKN6g1jBbFvy0MM85XwWcgGVKUmg7n4cH4qIFs7yRXvtou8sdBVePxeKFuHpJCCzFzeUAk9sDx8VHoTRGO/TFUBmAdkgtaDhLt7QrxGIrpvy388OdxxX/JboXNUbkoVGH6vO9QQxjyhXJCbmZh/Q==
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

Bill, I think grouper needs to keep track of which groups are managed by the loader via internally used attributes to make this happen right?





From: [mailto:] On Behalf Of Gettes, Michael
Sent: Monday, July 10, 2017 3:22 PM
To: Bill Thompson <>
Subject: Re: [grouper-users] Differencing tool with healing capabilities...


Right.  You are absolutely correct.  If grouper can figure all this out and “do the right thing”, that would be outstanding.  I guess this would mean the “healing” capability shouldn’t attempt to fix indirect memberships.  Would that do it?



On Jul 10, 2017, at 3:17 PM, William G. Thompson, Jr. <> wrote:


Just wondering about the scope of the feature and the use case.  If one is following the deployment guide then "fixing/healing" a user who needs access like another user may not necessarily involve manually updating direct members assignments. It could be an issue with upstream data for a reference group, could be an exception/addition to authZ policy, etc.






On Mon, Jul 10, 2017 at 3:07 PM, Gettes, Michael <> wrote:

Well, there is no real indication of how a group is being used in grouper - so I’m looking for a tool to do so independent of use.  Now, of course, it would be awesome if grouper could determine the use of a group and show differences and either automatically exclude certain differences (due to policy) or other constraints - but I think this is a wee bit further in the future.  Do I understand you correctly?



On Jul 10, 2017, at 2:54 PM, William G. Thompson, Jr. <> wrote:




This would work for ACL-like membership groups, but not for policy driven ones, right?  







On Mon, Jul 10, 2017 at 2:37 PM, Gettes, Michael <> wrote:

I was thinking (I know, always dangerous)…


If there was a grouper tool to show the differences of group memberships between 2 users and then 2 magic options (make user1 like user2, or make user2 like user1) - this would be a nice way of healing users who should have all the abilities of another.


Also, with the above UI tool, give me the option of selecting which groups to “heal” for the 2 users involved with checkboxes on each group.


I hope this makes sense and would be useful to others.  Maybe this has already been thunk up and in the hopper for some future development?


Thanks for your consideration.







Archive powered by MHonArc 2.6.19.

Top of Page