Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-40785

Users' Group Members Attribute are still pulled even though "Use the User Membership Attribute" has been ticked

    XMLWordPrintable

Details

    Description

      Summary

      Even though "Use the User Membership Attribute" has been ticked, Users' Group Members Attribute are pulled and copied to Confluence when users logged in to Confluence.

      This resulted in deletion of group membership every synchronization as Confluence re-writes the group membership based on the groups' User Membership Attribute

      Steps to Reproduce

      1. Have LDAP where users' group memberships are using Group Members Attribute (for example, UniqueMember). See the following sample Group LDIF:
      2. Set Confluence to connect with this LDAP. make sure that the Use the User Membership Attribute is ticked
      3. Test connection to Confluence.
        • Notice that the connection succeeded
        • Notice that membership test would usually fail
      4. Users are copied to Confluence.
        • Check their user details. they do not have any group membership
      5. Login to Confluence as this user.

      Expected Results

      Users are not able to log in to Confluence, as the user does not have a User Membership Attribute and therefore, does not belong to any group

      Actual Results

      1. Users are able to log in,
      2. The groups based on the Group Members Attribute are copied to Confluence

      However, this presents an issue as Upon LDAP synchronization, the group membership are deleted and rewritten, since the Confluence checks on the User Membership Attribute every time it synchronize to LDAP.

      This will result in users losing their group membership and having the "Not Permitted" page every time synchronization occurs, while they are still logged in.

      Attachments

        Activity

          People

            Unassigned Unassigned
            mkhairuliana Monique Khairuliana (Inactive)
            Votes:
            1 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: