Project

General

Profile

Actions

Defect #1233

closed

Unassigning one of the roles granting system account deletes and recreates account on end system.

Added by Peter Štrunc over 5 years ago. Updated over 5 years ago.

Status:
Rejected
Priority:
High
Assignee:
Peter Štrunc
Category:
Provisioning
Target version:
Start date:
08/30/2018
Due date:
% Done:

0%

Estimated time:
Affected versions:
Owner:

Description

To replicate this situation, use the following steps:

1. Create role "R" granting account on some system
2. Create organisation "O" with automatic role "R" assigned to it
2. Create user "U" with contract outside of this organisation
3. Assign role "R" directly to user "U"
4. Change contract position, so it now is on organisation "O"
5. Unassign role "R" which was assigned directly
6. You have arrived at your destination :) At this point there are DELETE and CREATE operations in provisioning queue

This needs to be fixed ASAP as it may completely break user account (change password, delete email messages, ...). Also take into consideration that some environments are slow, so grouping DELETE and CREATE into UPDATE may not be sufficient solution.

Affected version: 8.2.x

Actions

Also available in: Atom PDF