Skip to Content.
Sympa Menu

grouper-users - RE: [grouper-users] Grouper REST API for Privilege Inheritance

Subject: Grouper Users - Open Discussion List

List archive

RE: [grouper-users] Grouper REST API for Privilege Inheritance


Chronological Thread 
  • From: "Hyzer, Chris" <>
  • To: "Vachon, Thomas" <>, "" <>
  • Subject: RE: [grouper-users] Grouper REST API for Privilege Inheritance
  • Date: Tue, 7 Aug 2018 19:29:47 +0000
  • Accept-language: en-US
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:Rfi9+x9Ye5Yd/f9uRHKM819IXTAuvvDOBiVQ1KB+0+0XIJqq85mqBkHD//Il1AaPAd2Fraocw8Pt8InYEVQa5piAtH1QOLdtbDQizfssogo7HcSeAlf6JvO5JwYzHcBFSUM3tyrjaRsdF8nxfUDdrWOv5jAOBBr/KRB1JuPoEYLOksi7ze+/94HSbglSmDaxfa55IQmrownWqsQYm5ZpJLwryhvOrHtIeuBWyn1tKFmOgRvy5dq+8YB6/ShItP0v68BPUaPhf6QlVrNYFygpM3o05MLwqxbOSxaE62YGXWUXlhpIBBXF7A3/U5zsvCb2qvZx1S+HNsDtU7s6RSqt4LtqSB/wiScIKTg58H3MisdtiK5XuQ+tqwBjz4LRZoyeKfhwcb7Hfd4CRWRPQNtfVzBPDI2/YYsADesBMvpXoYbyvFYOsQK+CRWwCO/z1jNEmHn71rA63eQ7FgHG2RQtE9wMvnXUrdT6Kr0SXfiox6TWzTXDdfJW2Szz5IPVdR0hpO2DXbJwcMvQ10YvDRjIjlSLqYP5JT+Vy/wNvHad7+pmT+6glXMoqxxorzWp28wihI7JhocPxVDF8yV02Ic1JdukSEFle96kFoVftz2EO4dsXMwtXnxotSAnwbMFoZ62ZDYGx447yxLCbvGLbpWE7g/mWeafLjp0mG5pdbe9ihms/kWv1OjxW8yq3FpWrSdJisTAu34R2xDJ7sWLV+Fx8lm81TuLzQzf9+NJLEEsmarVNZEswaI8m58WvEjdHSL6hFn5gaqIeko45uel6OHqb7fiq5CAOIJ5jx3xProylsGwB+kzLxIAUHKB+eum0b3u5U35T6tOjv0xiqTXqIzXK8MHqqO2GgNYz54t5himAzehy9sXg2MLLFVYeBKblIfpPEzOIPblAvulm1SsijBrx+zYMbL9HpXNL3/DkLH7cbZ69k5c1A4zzddY55JXEL0OPPXzWkrpuNzZCB82LRC0zv75BNpnyo8SRGeCDrKEPK/PtFKI6O0iL/WQaIIQujvyNfco6ODrgHI8h1MRYaqk0YMSaH+iH/RmJ0uZYWDrgtcECWoKuxYxTOzqiVyDTzFTfW2/X6Mn5j4nEo6mEJ/DSZ6rgLyHxiu0AIBZZn1eBlCWDXjob5mEW+sLaC+KLc9hiDsEVaW5S4A/zxGirRL6y6F5IerO4S0Vrpbj1Nlu5+3PjhE+6yZ4D8Wb02GRUW50hGUISCEq3Kxhu0By1EqM0bUry8BfQJZt7vhJVQF+faLcyOlzEJq6Dh7BedKAU2G4S96mBjcZTtsr3dYUbwBwF8j0yliJ0DCtHqcYjfmWH5Eu6Yrd2WT8PcBw1yyA2aU8xRFyTdFIKHWrnOti7AXJHKbIlVmUjaCnaf5a0SLQojSt122L6Qt4QRx9S+GNdnAFZ1Cc5YD87UPTXbK0IbU8OU1c0cOELO1HZsC/3gYOf+vqJNmLOzH5oGy3Hxvdg+rUNNCwKWwAwCXQDlQFmAkP/HGAcBIzHTqlv3mAUG51DVy6ZUTq/KE+s369QkIuhyCyJ0x6n/vQmFYOgOCEDfYa37YKoiAk/jB/HEev0sj+CsGL4Rd5caNaJ94x/QQP2A==
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

Add a jira please and we will address this... probably by augmenting the
privilege assignment WS and not by worrying about the underlying attribute
assignments.

Or let me know and I can add a jira for you.

Thanks
Chris

-----Original Message-----
From: Vachon, Thomas
[mailto:]

Sent: Tuesday, August 07, 2018 3:07 PM
To: Hyzer, Chris
<>;


Subject: Re: [grouper-users] Grouper REST API for Privilege Inheritance

Yea, we mean via grouper-ws.

We can do it in the GUI, any groups or stems made after the inherit privilege
is granted automatically gets the parents permissions.
________________________________________
From: Hyzer, Chris
<>
Sent: Tuesday, August 7, 2018 15:00
To: Vachon, Thomas;

Subject: RE: [grouper-users] Grouper REST API for Privilege Inheritance

When you say "API" you mean WS right? If you give someone CREATE or ADMIN
that doesn't inherit to descendant objects...

-----Original Message-----
From: Vachon, Thomas
[mailto:]
Sent: Tuesday, August 07, 2018 2:58 PM
To: Hyzer, Chris
<>;


Subject: Re: [grouper-users] Grouper REST API for Privilege Inheritance

Thanks Chris,

I don't quite grok the inherit problem still. We want to set this up fully
via the API. ll we do is give a known group CREATE on the stems and ADMIN on
the groups on the top of the "local" stem
________________________________________
From: Hyzer, Chris
<>
Sent: Tuesday, August 7, 2018 14:55
To: Vachon, Thomas;

Subject: RE: [grouper-users] Grouper REST API for Privilege Inheritance

You can do composite groups with GroupSave.

https://spaces.at.internet2.edu/display/Grouper/Group+Save

For the inherited privs, in the UI it calls a method to inherit. But it will
also inherit from a daemon which runs nightly. If you want it to run when
you save a rule over WS, please open a jira and be explicit about the calls
that you use to configure the privileges...

Thanks
Chris

-----Original Message-----
From:


[mailto:]
On Behalf Of

Sent: Tuesday, August 07, 2018 2:47 PM
To:

Subject: [grouper-users] Grouper REST API for Privilege Inheritance

Hi everyone,

We are trying to move automation more into the REST/grouper-ws land from the
GCLI where possible. We have hit a wall on setting up inherited Grouper
permissions on a stem.

As you all know, but I'm going to say anyways, if you don't set the permission
inheritance up first, any groups and stems created don't get retroactively
applied permissions. Since we do highly decentralized management, this poses
a large problem for us.

We have group, stem, and single-execution permissions setup via the API but I
am unable to decipher what needs to happen to get inherited permissions
applied via the API. I will be committing this back to the community, so any
help is appreciated.

Also, for extra credit, if you can help me get composite groups working, that
would save us a bit more time as well.

Thank You,
Tom Vachon



Archive powered by MHonArc 2.6.19.

Top of Page