Bug 747741 - command: ipa selfservice-mod : provide wrong attr for --attrs delete a selfservice permission
Summary: command: ipa selfservice-mod : provide wrong attr for --attrs delete a self...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: ipa
Version: 6.2
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: rc
: ---
Assignee: Rob Crittenden
QA Contact: IDM QE LIST
URL:
Whiteboard:
Depends On:
Blocks: 756082
TreeView+ depends on / blocked
 
Reported: 2011-10-20 21:40 UTC by Yi Zhang
Modified: 2013-05-23 14:18 UTC (History)
4 users (show)

Fixed In Version: ipa-2.2.0-1.el6
Doc Type: Bug Fix
Doc Text:
No documentation needed.
Clone Of:
Environment:
Last Closed: 2012-06-20 13:15:40 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2012:0819 0 normal SHIPPED_LIVE ipa bug fix and enhancement update 2012-06-19 20:34:17 UTC

Description Yi Zhang 2011-10-20 21:40:30 UTC
Description of problem:
example: such command : ipa  selfservice-mod "edit address" --attrs="nosuchattr"
will delete selfservice permission "edit address" from ipa server


Version-Release number of selected component (if applicable):
[yi@i386a(101) ~] rpm -qi ipa-server
Name        : ipa-server                   Relocations: (not relocatable)
Version     : 2.1.3                             Vendor: Red Hat, Inc.
Release     : 2.el6                         Build Date: Tue 18 Oct 2011 11:12:34 AM PDT
Install Date: Thu 20 Oct 2011 10:39:05 AM PDT      Build Host: x86-002.build.bos.redhat.com
Group       : System Environment/Base       Source RPM: ipa-2.1.3-2.el6.src.rpm
Size        : 3355311                          License: GPLv3+
Signature   : (none)
Packager    : Red Hat, Inc. <http://bugzilla.redhat.com/bugzilla>
URL         : http://www.freeipa.org/
Summary     : The IPA authentication server
Description :
IPA is an integrated solution to provide centrally managed Identity (machine,
user, virtual machines, groups, authentication credentials), Policy
(configuration settings, access control information) and Audit (events,
logs, analysis thereof). If you are installing an IPA server you need
to install this package (in other words, most people should NOT install
this package).


How reproducible: always


Steps to Reproduce:
1. install ipa server
2. create selfservice permission
[yi@i386a(101) ~] ipa selfservice-add "edit address" --permission=write,read --attrs=l
--------------------------------
Added selfservice "edit address"
--------------------------------
  Self-service name: edit address
  Permissions: write, read
  Attributes: l

3. modify this permission by providing wrong attr value
[yi@i386a(101) ~] ipa  selfservice-mod "edit address" --attrs="nosuchattr"
ipa: ERROR: targetattr "nosuchattr" does not exist in schema. Please add attributeTypes "nosuchattr" to schema if necessary. ACL Syntax Error(-5):(targetattr = \22nosuchattr\22)(version 3.0;acl \22selfservice:edit address\22;allow (write,read) userdn = \22ldap:///self\22;): Invalid syntax.

-- the return message is correct, but the permission is disappeared from ipa server, 

[yi@i386a(101) ~] ipa selfservice-find "edit address"
----------------------
0 selfservices matched
----------------------
----------------------------
Number of entries returned 0
----------------------------

  
Actual results:


Expected results:


Additional info: no error msg found in /var/log/httpd/error_log

Comment 2 Dmitri Pal 2011-10-20 22:26:28 UTC
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/2014

Comment 5 Scott Poore 2012-03-16 20:33:37 UTC
Verified.

Version :: ipa-server-2.2.0-4.el6.x86_64

Automated Test Results ::

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: selfservice_bz_747741 ipa selfservice-mod provide wrong attr for --attrs delete a selfservice permission
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

:: [   LOG    ] :: BZ Test Running: ipa selfservice-mod selfservice_bz_747741 --attrs=badattrs > /tmp/tmp.V5BS5xp3mS/selfservice_bz_747741.10021.out 2>&1
:: [   LOG    ] :: Duration: 12s
:: [   LOG    ] :: Assertions: 0 good, 0 bad
:: [   PASS   ] :: RESULT: selfservice_bz_747741 ipa selfservice-mod provide wrong attr for --attrs delete a selfservice permission

Manual Test Results ::



[root@hp-xw6600-01 ipa-selfservice]# ipa selfservice-add bz747741 --attrs=l
----------------------------
Added selfservice "bz747741"
----------------------------
  Self-service name: bz747741
  Permissions: write
  Attributes: l


[root@hp-xw6600-01 ipa-selfservice]# ipa selfservice-mod bz747741 --attrs=badattr
ipa: ERROR: targetattr "badattr" does not exist in schema. Please add attributeTypes "badattr" to schema if necessary. ACL Syntax Error(-5):(targetattr = \22badattr\22)(version 3.0;acl \22selfservice:bz747741\22;allow (write) userdn = \22ldap:///self\22;): Invalid syntax.


[root@hp-xw6600-01 ipa-selfservice]# ipa selfservice-show bz747741
  Self-service name: bz747741
  Permissions: write
  Attributes: l

[root@hp-xw6600-01 ipa-selfservice]# ipa selfservice-find bz747741---------------------
1 selfservice matched
---------------------
  Self-service name: bz747741
  Permissions: write
  Attributes: l
----------------------------
Number of entries returned 1
----------------------------

Comment 7 Martin Kosek 2012-04-18 20:50:42 UTC
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
No documentation needed.

Comment 9 errata-xmlrpc 2012-06-20 13:15:40 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2012-0819.html


Note You need to log in before you can comment on or make changes to this bug.