[ 
https://issues.apache.org/jira/browse/SLING-3144?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13790352#comment-13790352
 ] 

Antonio Sanso commented on SLING-3144:
--------------------------------------

thanks [~bdelacretaz] 

bq. In addition, I would suggest having a look at the CreateUserServlet and 
CreateGroupServlet, and make sure they return a 403 forbidden HTTP status and 
log a descriptive message if these groups are missing.

another option is to change the default of the properties that expect those 
groups to empty. IMHO is wrong to count on the presence of them.

WDYT?



> UserAdmin and GroupAdmin groups are missing on our Oak setup
> ------------------------------------------------------------
>
>                 Key: SLING-3144
>                 URL: https://issues.apache.org/jira/browse/SLING-3144
>             Project: Sling
>          Issue Type: Bug
>            Reporter: Bertrand Delacretaz
>            Assignee: Bertrand Delacretaz
>            Priority: Minor
>         Attachments: SLING-3144-patch.txt
>
>
> Some of my SLING-2788 integration tests (for example PrivilegesInfoTest) fail 
> as the UserAdmin and GroupAdmin don't initially exist.
> In Jackrabbit those groups are apparently created by 
> UserAccessControlProvider [1] - I'll ask the Oak team how to have the 
> equivalent in Oak.
> As a workaround, creating those groups as follows allows a few more tests to 
> pass - but for the final setup the groups need to be created with specific 
> security-related parameters.
> curl -u admin:admin -F:name=GroupAdmin 
> http://localhost:8080/system/userManager/group.create.html
> curl -u admin:admin -F:name=UserAdmin 
> http://localhost:8080/system/userManager/group.create.html
> [1] 
> http://jackrabbit.apache.org/api/2.2/org/apache/jackrabbit/core/security/user/UserAccessControlProvider.html



--
This message was sent by Atlassian JIRA
(v6.1#6144)

Reply via email to