-
Bug
-
Resolution: Fixed
-
Medium
-
2.10
-
None
-
6
-
A user removed/deleted directly from LDAP is removed from the User browser, but the Can Use permissions are still associated with it, adding to the license count.
The Can-Use permissions should be revoked for this user when removed from LDAP.
To replicate:
1) Delete a user directly from the LDAP server, ensuring the user is a member of a group with "Can Use" permissions
2) Check that the user does not appear in the user browser
3) The license count still includes this deleted user
4) The EXTERNAL_MEMBERS still have the group memberships
- is duplicated by
-
CONFSERVER-12786 Removed LDAP users still has remaining permission in Confluence database
-
- Closed
-
-
CONFSERVER-16445 Unable to delete LDAP user from Confluence group when they are no longer in LDAP
-
- Closed
-
- relates to
-
CONFSERVER-19124 Encountered NullPointerException due to dangling permission left after an LDAP group or user is deleted from the LDAP server
-
- Closed
-
-
CONFSERVER-11467 People Directory empty or not displaying the proper number of people - When users have been deleted from an External User Management
-
- Closed
-
This issue was fixed with Confluence 3.5. Users which aren't found in LDAP will be no longer counted towards the license count after the next sync with LDAP (or until the user is manually removed, if an "Internal with LDAP authentication" directory is used). The user's personal space will no be longer accessible.
However, the user will not be removed from the people directory. That issue is tracked as
CONF-11467.A related issue around page permissions not working with removed users,
CONF-19124, is fixed in Confluence 3.5.12 and later.Edit: sorry, that's Confluence 3.5.