Skip to Content.
Sympa Menu

grouper-users - [grouper-users] Re: Grouper 2.4 UI problem with Setting Attributes

Subject: Grouper Users - Open Discussion List

List archive

[grouper-users] Re: Grouper 2.4 UI problem with Setting Attributes


Chronological Thread 
  • From: Brett Bieber <>
  • To: "Coleman, Erik C" <>, "" <>
  • Subject: [grouper-users] Re: Grouper 2.4 UI problem with Setting Attributes
  • Date: Tue, 30 Oct 2018 13:23:43 +0000
  • Accept-language: en-US
  • Ironport-phdr: 9a23:UBeQ/RZNRdJsFPyp5c7vCaz/LSx+4OfEezUN459isYplN5qZpsyzYh7h7PlgxGXEQZ/co6odzbaO7Oa4ASQp2tWoiDg6aptCVhsI2409vjcLJ4q7M3D9N+PgdCcgHc5PBxdP9nC/NlVJSo6lPwWB6nK94iQPFRrhKAF7Ovr6GpLIj8Swyuu+54Dfbx9HiTahY75+Ngm6oRnMvcQKnIVuLbo8xAHUqXVSYeRWwm1oJVOXnxni48q74YBu/SdNtf8/7sBMSar1cbg2QrxeFzQmLns65Nb3uhnZTAuA/WUTX2MLmRdVGQfF7RX6XpDssivms+d2xSeXMdHqQb0yRD+v6bpgRh31hycdLzM38H/ZhNFsjKxVoxyhqR5ww4/Ib46aL/d+ZL/Rcc8ASGZdQspcVypMCZ68YYsVCOoBOP5VopTnp1QQsRu+GRSnCf7uyjBWnXD5w7c62PkmHA7dxgwvAc4OsGjOoNruNacdT/u6w7fSzTjYafNZxyzy6JLSfRA6ovGDR6h8ftTMxkkyDg7IiEibp4LiPzOQzOsNsm6b4vJhVeKrj24nqgdxoj+uxsc3kIXGmJ8ayk3c+SV53IY1OcW4SFVmbt6lHptQuT+VN5FoTcMkX25npjg1yqMYtp69YCgKyJMnxwPQa/yHb4iI4gzsW/uWITd9nn1lebS/hxCo/kil1OL9WNO70E1WripFjNbMrWoC1xnN5cSdS/t95UGs0iuM2QDL8uxIPE85mKnBJ5I8w7M9mIAfvVnMEyL4gkn6kaCbe0c89uS19ejqZq/qq5uSOoNulw3zMaUjltaiDeglPAUCR2ab9vq/2bH/+ED0RahFg/82n6Tcq5/XJd8UqbC8DgBL0Iss9ReyAjK839kXmXQIMFRIcw+dgYfzIVHBOvX4AO+/g1uylDdrwOjLPrjuA5nRNXfPiavtcapj50NTyQc+wsxT64xOBrEZOPLzWkjxtMfEDhAnLgO42froCNJ41o8GWGKPBLGWML/KvFOV6e8iIPOAaJIUtTvzMfQp+vHjgHEjlVMAcqSk34MbaHWiEfRnJ0WZb2DsgtAEEWoSpgo+VvLqiEaaXDJPZHu/UL8w6iw/BY26D4rOSYSgjaSa0yehAJJWenxGBkqXHnfpaYqLQOkDaDiJL89njDMLTqKhRJU61RGtrgD20aRoIffJ+iEAr5LsyMB15/HPlRE17TF0AN6d02aQT2FsgGwIXSY63L1koUNj0FeDyrN1g/hZFdxI+/NJSRk2OYTdz+x8F9D9RBjBftGXR1a6XNmqGy8+Qc8sw4xGX0EoUf6lih3G1izuS5IPlr/DL9Z8pq/X1FDwI8J8zXHHz+8sg0RwBoMFOnehm7Zy7U3OHIPTiG2Ykbqnb6IRwHSL+WuehyLas1tfTRZ9S+DYRn0FfWPXq8j0/EXPU+XoBLg6ZFhv08mHf4FQZ8H1xX9HSf3uIpyKaXi8h3v2DxeFzL6WRIzncX8UxybUTkUIjlZArj69KQEiC3L58CrlBzt0GAe3bg==
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

Hi Erik,

We're doing the same here at Nebraska and not having any issues, so I don't think it's a UI bug. I can't tell in the first screenshot if you were accessing the site securely or not, but I noticed the error message indicated an http vs https difference even though the domain name was the same. Is it possible you were accessing the site via an insecure URL and the config is set to https? We've got ours configured to redirect any requests to http:// to https:// at the load balancer. Hope that helps.

-Brett


From: <> on behalf of Coleman, Erik C <>
Sent: Monday, October 29, 2018 6:09:00 PM
To:
Subject: [grouper-users] Grouper 2.4 UI problem with Setting Attributes
 

I’m running into a snag with the new Grouper 2.4 (running from container tier/grouper:2.4.0-a2-u0-w0-p0).  I’m wanting to demonstrate how group owners can selectively choose to have their groups or folders sync to our AD via our PSPNG config. I select a group or folder and choose “More Actions” -> “Attribute Assignments” and assign an attribute, it seems to work, but then I get this strange error “ErrorType; LoadXML Description: Incorrect XML”:

 

 

Then if I click OK, then attempt to choose the action to assign a value to that attribute, I get a remarkably blank screen:

 

 

The only interesting log entries I am seeing is this:

 

grouper-api;grouper_error.log;as-aws-test-dev2;aws-poc;2018-10-29 18:05:26,238: [ajp-nio-8009-exec-3] ERROR CsrfGuardLogger.log(47) - - potential cross-site request forgery (CSRF) attack thwarted (user:ecc, ip:xxx.xxx.xxx.xxx, method:POST, uri:/grouper/grouperUi/app/UiV2GroupAttributeAssignment.assignmentMenuAddValue, error:request token does not match session token)

 

grouper-api;grouper_error.log;as-aws-test-dev2;aws-poc;2018-10-29 18:05:26,475: [ajp-nio-8009-exec-4] ERROR CsrfGuardLogger.log(47) - - Referer domain https://authman-test.techservices.illinois.edu/grouper/grouperUi/app/UiV2Main.index?operation=UiV2GroupAttributeAssignment.assignmentMenuAddValue&attributeAssignId=635adbb3af3b4c2fa54a8eafca18ee13&csrfExtraParam=xyz does not match request domain: http://authman-test.techservices.illinois.edu/grouper/grouperExternal/public/OwaspJavaScriptServlet

 

Is this a UI bug? Or possibly a sign I’ve got something corrupted somewhere?  It’s still pretty stock test environment otherwise.

 

Thanks,

 

Erik Coleman

University of Illinois at Urbana-Champaign

 




Archive powered by MHonArc 2.6.19.

Top of Page