Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-4849

User loses all local group memberships if LDAP sync is unable to find the user, but the user appears again in subsequent syncs

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Medium Medium
    • None
    • None
    • None

      (from original issue in CONF-28621)

      Steps to Reproduce

      1. Add a connection to LDAP in Confluence Admin >> User Directories with the Read Only, with Local Groups option
      2. Sync the directory and make sure that LDAP users are returned
      3. Add 1 LDAP user to a local group (membership)
      4. Change the User Object Filter in the directory's configuration in Confluence Admin >> User Directories to a dummy filter, such as the following:
        (&(objectclass=inetorgperson)(cn=dummynonexistentuser))
        
      1. Sync the directory again (Notice that the LDAP users are missing)
      2. Revert the User Object Filter to the previous working filter
      3. Sync the directory again (notice that the LDAP users are back, but their local group memberships are gone)

       

            [CWD-4849] User loses all local group memberships if LDAP sync is unable to find the user, but the user appears again in subsequent syncs

            Alex Lam added a comment - https://getsupport.atlassian.com/servicedesk/customer/portal/41/PSSRV-30682 https://getsupport.atlassian.com/servicedesk/customer/portal/41/PSSRV-30700

            It's 2021 and still a bug.

            Joeran ZELLER added a comment - It's 2021 and still a bug.

            When an LDAP filters is changed and contains a mistake (typo, wrong usage of syntax, ...) we potentially lose all users. When reverting to the original filter all groups are vanished. This is a real pain!

             

            Crowd directories should have a setting to keep local groups for vanished users. It should be a choice because for some companies it might not be desirable.

            Charlie Misonne added a comment - When an LDAP filters is changed and contains a mistake (typo, wrong usage of syntax, ...) we potentially lose all users. When reverting to the original filter all groups are vanished. This is a real pain!   Crowd directories should have a setting to keep local groups for vanished users. It should be a choice because for some companies it might not be desirable.

             We are still facing the same problems  in Confluence 6.15.1. When will fix this?

            Юлия Михайлова added a comment -  We are  still  facing  the same problems   in Confluence 6.15.1. When will fix this?

              pniegowski Pawel Niegowski (Inactive)
              pniegowski Pawel Niegowski (Inactive)
              Affected customers:
              18 This affects my team
              Watchers:
              23 Start watching this issue

                Created:
                Updated: