Defect #635
closedAutomatic role approver needs ROLE_REQUEST_EXECUTE authority
100%
Description
The approver of automatic role assignment to any node in organization structure needs ROLE_REQUEST_EXECUTE authority, otherwise the role assignment to users will fail on insufficient app privileges.
Exception is thrown in DefaultIdmRoleRequestService:210.
The problem here is that role request is made, but it deliberately fails on these privileges, which leads to broken role requests and automatic role assignment status.
In my opinion this is a bug, otherwise please provide a description of application privileges setup, ideally in as a documentation. Thanks!
Updated by Radek Tomiška over 6 years ago
- Tracker changed from Task to Defect
- Status changed from New to Needs feedback
- Assignee changed from Radek Tomiška to Vít Švanda
- % Done changed from 0 to 90
This is bug, I've fixed it:
https://github.com/bcvsolutions/CzechIdMng/tree/rtomiska/635-role-request-execute-rights
Could you pls do a feedback?
Updated by Vít Švanda over 6 years ago
- Status changed from Needs feedback to Closed
- Assignee changed from Vít Švanda to Radek Tomiška
- % Done changed from 90 to 100
I saw and fully agree.
Updated by Radek Tomiška over 6 years ago
Thx for review, i've merged it into develop and hotfix/7.3.1 branch (citrine).