Project

General

Profile

Actions

Defect #2415

closed

Business roles has subroles with mapped system and merge attribute. When you delete for example 2 subroles, one of them still remain on the end system

Added by Roman Kučera almost 4 years ago. Updated over 3 years ago.


Description

Use case:
Business role "role" has 3 subroles:
"subrole 1" - has mapped system system and override multivalue merge attribute
"subrole 2" - has mapped system system and override multivalue merge attribute
"subrole 3" - has mapped system system and override multivalue merge attribute

You have some user which has account on this end system and has role "role"
If you delete for example 2 subroles from "role" together, one of them will still remain on the end system. E.g remove "subrole 1" and "subrole 2" by checking checkbox and deleting one of them will still remain on the end system.
It looks like that provisioning is executed before the role is removed from user in IdM.

Result:
User has still some permission on end system until next re-save for this user.

Workaround:
Re-save all users after you delete some subroles?


Related issues

Related to IdStory Identity Manager - Task #1636: Redesign business roles assignmentClosedRadek Tomiška05/06/2019

Actions
Related to IdStory Identity Manager - Task #2498: Automatic roles: prevent to recount automatic roles simultaneouslyClosedRadek Tomiška09/22/2020

Actions
Actions

Also available in: Atom PDF