Skip to Content.
Sympa Menu

grouper-users - [grouper-users] Subject cannot groupAttrRead

Subject: Grouper Users - Open Discussion List

List archive

[grouper-users] Subject cannot groupAttrRead


Chronological Thread 
  • From: Jutta Biernath <>
  • To:
  • Subject: [grouper-users] Subject cannot groupAttrRead
  • Date: Thu, 24 Aug 2017 14:02:38 +0000 (UTC)
  • Ironport-phdr: 9a23:CTOkPh98y54R0P9uRHKM819IXTAuvvDOBiVQ1KB42+kcTK2v8tzYMVDF4r011RmSDNWds6oMotGVmpioYXYH75eFvSJKW713fDhBt/8rmRc9CtWOE0zxIa2iRSU7GMNfSA0tpCnjYgBaF8nkelLdvGC54yIMFRXjLwp1Ifn+FpLPg8it2e2//57ebx9UiDahfLh/MAi4oQLNu8cMnIBsMLwxyhzHontJf+RZ22ZlLk+Nkhj/+8m94odt/zxftPw9+cFAV776f7kjQrxDEDsmKWE169b1uhTFUACC+2ETUmQSkhpPHgjF8BT3VYr/vyfmquZw3jSRMsrqQL06Wzmv4b5nRAP1hCwaMzI0/2Xahsl2galGohyuugZ/zpbKbo+VKfRxfKDTctwGSmROWchfWTdMAp+hYYYVE+YMJ/pUo5f7qlATrRW+Hw6sBOb3xzFMm3/2wbE63P48Ggzb3QwvAcgOsHLOo9XpNKcZTOe4zKvVzTXfc/NZwy3x55PJch8/u/GMW6h/cdbRyUQ0GQPFk0ycppf7MDOP0uQNsm6b4/B9Wu2xkmMqrRx6rDu3xso0lIXFmoAYxkrG+Ch52oo5ONy1RUFhbdK6DpdcqieXPJZsTMw4WWFnoiM6x6UGuZGleCgKz4wqxxrea/ycb4iI+QzvWPyQITd+mHJqZqi/hxCs/ki81OHwTNe730tXriZdk9nMsG4C1wDL58SZVvdw/F2t1DSP2gzJ9+1JIE85mbDFJ5I/37I8jp8Tvl7CHi/ylkX2lqiWdkA89+iw9uToea7mp5+ZN49skA7zKaUumsqjAesmKAgOWXaU+fii2LH540L2XahKguUskqbFqJDaOdgbpqmhDg9ayIYj7Au/Dy+439QChHUHMUlFdwydj4jyIFzOJPH4Deyjg1S3jjtn3fHGPrv9AprTNHjDlqnufapj50JG1gU80M1ftNpoDeQOOvXuQkLr8cHDAwUiGw2y3+v9DthhjMUTVX/cLLWeNfbwrEOU76oFIuSWYoYJuH6pKeU5+/eoh340g1kUYamB04ZSYn2iGvVgZUmUNym/yuwdGHsH61JtBNfhj0ePBGICag==

Hello,

I have recently introduced a group attribute via AttributeFramework which is
now already assignd to several groups. As long as a wheel group member works
with it, everything works fine.

There are also users that have to be able to assign and handle this attribute
themselves without being member of the wheel group. For them I have edited the
group mask in the NewUI so that the can assign it if they want. Also this
works - as long as a wheel group member does it.

For making sure that the named users can handle that too I have made them
admins of the group as well as admins of the attribute. I.e. I have given them
ALL privileges I could, at least via NewUI and LiteUI.

Now the problem: If one of the other users tries to assign this attribute via
NewUI he gets the message "Insufficient privileges". Checking the log files of
the web application I find:

"Insufficient privilege exception for group create: 'xxx'/'person'/'xxx'
edu.internet2.middleware.grouper.exception.InsufficientPrivilegeException:
Subject Subject id: xx, sourceId: xxx cannot groupAttrRead"

I have understood that the privilege "groupAttrRead" came along with the
upgrade to Grouper 2.2, but there seems to be no way to assign this privilege
anywhere in the UIs. In the source code I found it in AccessPrivilege.java;
can you please give me an example of how to handle that? Is it planned to
include it in one of the UIs?


Thank you,

Jutta Biernath
FU Berlin



Archive powered by MHonArc 2.6.19.

Top of Page