Skip to Content.
Sympa Menu

grouper-users - Re: [grouper-users] Grouper REST API for Privilege Inheritance

Subject: Grouper Users - Open Discussion List

List archive

Re: [grouper-users] Grouper REST API for Privilege Inheritance


Chronological Thread 
  • From: "Vachon, Thomas" <>
  • To: "Black, Carey M." <>
  • Cc: "Hyzer, Chris" <>, "" <>
  • Subject: Re: [grouper-users] Grouper REST API for Privilege Inheritance
  • Date: Tue, 7 Aug 2018 22:15:02 +0000
  • Accept-language: en-US
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:8pngiBU/mtjFEHe/mrasEiSo32DV8LGtZVwlr6E/grcLSJyIuqrYZRSBvKdThVPEFb/W9+hDw7KP9fy4BypYud6oizMrSNR0TRgLiMEbzUQLIfWuLgnFFsPsdDEwB89YVVVorDmROElRH9viNRWJ+iXhpTEdFQ/iOgVrO+/7BpDdj9it1+C15pbffxhEiCCybL9uLRi6txndutULioZ+N6g9zQfErGFVcOpM32NoIlyTnxf45siu+ZNo7jpdtfE8+cNeSKv2Z6s3Q6BWAzQgKGA1+dbktQLfQguV53sTSXsZnxxVCAXY9h76X5Pxsizntuph3SSRIMP7QawoVTmk8qxmUwHjhjsZODEl8WHXks1wg7xdoBK9vBx03orYbJiIOPZiYq/ReNUXTndDUMlMTSxMGoOyYZUSAeodM+hWrIf9qFkPrRSiCgahH/nvxiNNhnLswaE2z+YsHAfb1wIgBdIOt3HUoc37OKgdS++60KnIzTLFb/9OxDzz9ojIchckof6WRrJ8f9faxE4zFwPFiVWQrJbqPyiN2eQTqWeU8+pgVeWpi2M8qwF+uCKvxtk2hYnTm40Z0E7L+jhkwIssI9CzVUB1YdmhEJRKtiGaMZN7QsIkQ2F0pik60LsGtoCnfCQU0pgo2QPQa+Gff4iQ+BLjU+GRITlghHJiebK/gQqy/VK8xe37U8m51ktBoCldktTUuX0Bywbf5tWbRvZ/5Eus2yiD2xrQ5+xGOUw4i6vWJ4I8zrM1i5YetUDOEyr5lUj5j6KaakAp9+aq5unjf7nro5GcOoBohg7gN6kjnsyyDvg6PwULX2WX5+ax1LPm8EHkXblFkOA5nrHXsJ/EJskXuqu0DgpL3ok/6BuyDTKr3dAEkXYcL19IfRCKgJPzNFzOJf33EOmwj0isnTpt2vvIJKfuAo/XIXjGiLrhfahy60pbyAcr1d5S+5VaBq0BLf7qREL/rcHUAgY+MwOv3enrEtJ91p4CWW2UBa+ZLaXSvkKS6uI3OemMY5MVtyjhJPg55v7uink5lUUafam0wZsXbHe4HvNlI0mDfXXshdIBHX8Lvgo4UuPqlEWPXDFPa3qoQq4w+jM2BJikAIvdXIygg76M0D++HpJMZ2BGDl6MEW3vd4WBQ/oMdCKSIshkkjMeTriuU5Eh2guyuw/6zLpnKPHZ+i0CupL5yth6/ffTmgwo+TNqEsudznmBT3tokWMQWz82wKd/rFRyyleZ1qh4nuRYGsJJ5/9QTwc6LoDTz/ZhC93pXgLBf8yJSEq9Qtm4Gz0xT9Qxw8MQbEZnHdWtkAzD0zSwD7ALirOLGc98zqWJlVL1Ls1+jz7t3bMsnhEDBIEHYWeij6V8sVGJXKbOiFjfmqq3I/cyxinIoS29xGGOu0ccGDJwVqDMRjpXMlfWqtHw/XTcRrSuDrIPMgJb18eYJu1HZsC/3gYOf+vqJNmLOzH5oGy3Hxvdg+rUNNCwKWwAwCXQDlQFmAkP/HGAcBIzHTqlv3mAXG51DVy6ZUTq/KE+s369QkIuhyCyJ0x6n/vQmFYOgOCEDfYa37YKoiAk/il0G1O0xOXIAtGAoAxJfKxGf9on7BFK2X+K/wE=
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

We are on 2.3.0 and not fully patched either. We hit some buggy patches which made us more cautious. Likely we won’t do major patching until 2.4 releases unless we have a very good reason

Sent from my iPhone

On Aug 7, 2018, at 4:15 PM, Black, Carey M. <> wrote:

Tom,

 

I note that I do not see the version that you are using.... So I will assume you are fully patched! ( Ha... You should have said otherwise. :) )

 

 

There are WS calls to " Assign Attributes" https://spaces.at.internet2.edu/display/Grouper/Assign+Attributes or https://spaces.at.internet2.edu/display/Grouper/Assign+Attributes+Batch

 

You could add the " inherit to descendant " rules on folders that way. ( It is harder than you want it to be but it could be done.)

 

To explain more of what I mean... use the New UI patch 44 and you can see the details of the attributes that are the "inherit" rules.

 

To the Demo Server.... https://grouperdemo.internet2.edu/grouper_v2_3/

 

I created a folder and added "Admin privileges" for Groups, Folders, and Attributes for (one folder deep) for a "random user" on the system. J

 

<image001.png>

 

Then look at the attributes assigned to the folder.

 

<image003.png>

 

Below are the attributes that ONLY do the “Group” inheritance portion. There are three separate sets of these for the other “Folder” and “Attribute” inheritance rules.

 

<image004.png>

 

So for each type of inheritance the there is an attribute assignment of “rule” ( part of the rulesTypeDef ).

Then there are a set of attribute assignments to the assignment of the “rule” to the folder ( ruleActAsSubjectId, ruleActAsSubjectSourceId, …. ) with values a needed.

 

I would not relish doing it with the current WS. However, the “Assign+Attributes+Batch” might make it a single call. Not a simple one… but one.

 

Maybe that will help…?

 

--

Carey Matthew

 

 

-----Original Message-----
From: <> On Behalf Of Hyzer, Chris
Sent: Tuesday, August 7, 2018 3:30 PM
To: Vachon, Thomas <>;
Subject: RE: [grouper-users] Grouper REST API for Privilege Inheritance

 

Add a jira please and we will address this...  probably by augmenting the privilege assignment WS and not by worrying about the underlying attribute assignments.

 

Or let me know and I can add a jira for you.

 

Thanks

Chris

 

-----Original Message-----

From: Vachon, Thomas []

Sent: Tuesday, August 07, 2018 3:07 PM

To: Hyzer, Chris <>;

Subject: Re: [grouper-users] Grouper REST API for Privilege Inheritance

 

Yea, we mean via grouper-ws.

 

We can do it in the GUI, any groups or stems made after the inherit privilege is granted automatically gets the parents permissions.

________________________________________

From: Hyzer, Chris <>

Sent: Tuesday, August 7, 2018 15:00

To: Vachon, Thomas;

Subject: RE: [grouper-users] Grouper REST API for Privilege Inheritance

 

When you say "API" you mean WS right?  If you give someone CREATE or ADMIN that doesn't inherit to descendant objects...

 

-----Original Message-----

From: Vachon, Thomas []

Sent: Tuesday, August 07, 2018 2:58 PM

To: Hyzer, Chris <>;

Subject: Re: [grouper-users] Grouper REST API for Privilege Inheritance

 

Thanks Chris,

 

I don't quite grok the inherit problem still.  We want to set this up fully via the API. ll we do is give a known group CREATE on the stems and ADMIN on the groups on the top of the "local" stem

________________________________________

From: Hyzer, Chris <>

Sent: Tuesday, August 7, 2018 14:55

To: Vachon, Thomas;

Subject: RE: [grouper-users] Grouper REST API for Privilege Inheritance

 

You can do composite groups with GroupSave.

 

https://spaces.at.internet2.edu/display/Grouper/Group+Save

 

For the inherited privs, in the UI it calls a method to inherit.  But it will also inherit from a daemon which runs nightly.  If you want it to run when you save a rule over WS, please open a jira and be explicit about the calls that you use to configure the privileges...

 

Thanks

Chris

 

-----Original Message-----

From: [] On Behalf Of

Sent: Tuesday, August 07, 2018 2:47 PM

To:

Subject: [grouper-users] Grouper REST API for Privilege Inheritance

 

Hi everyone,

 

We are trying to move automation more into the REST/grouper-ws land from the

GCLI where possible.  We have hit a wall on setting up inherited Grouper

permissions on a stem.

 

As you all know, but I'm going to say anyways, if you don't set the permission

inheritance up first, any groups and stems created don't get retroactively

applied permissions.  Since we do highly decentralized management, this poses

a large problem for us.

 

We have group, stem, and single-execution permissions setup via the API but I

am unable to decipher what needs to happen to get inherited permissions

applied via the API.  I will be committing this back to the community, so any

help is appreciated.

 

Also, for extra credit, if you can help me get composite groups working, that

would save us a bit more time as well.

 

Thank You,

Tom Vachon

PNG image

PNG image

PNG image




Archive powered by MHonArc 2.6.19.

Top of Page