Hi Andrea,

Yes that’s what I thought, but shouldn’t the web interface show an error 
message rather than throw an exception?

However I didn’t think that a GROUP_ADMIN should be able to edit and delete a 
user that isn't a member of any group.

Rob

From: [email protected] [mailto:[email protected]] On Behalf Of Andrea 
Aime
Sent: 04 April 2017 17:30
To: Langford, Robert <[email protected]>
Cc: GeoServer Mailing List List <[email protected]>
Subject: Re: [Geoserver-users] Possible bug GROUP_ADMIN deleting users

Hi,
that seems like legit behavior, if I understand things correctly (and I might 
not) a group admin
administers a particular group, so cannot touch users in other groups.

To do that one needs to have the ROLE_ADMINISTRATOR, which is the global 
administrator instead

Cheers
Andrea


On Tue, Apr 4, 2017 at 6:05 PM, Rob L 
<[email protected]<mailto:[email protected]>> wrote:
Sorry looks like the exception text might have gotten stripped out in Nabble
here it is below:

> Caused by: java.lang.RuntimeException: java.io.IOException:
> User Username: a-different-group-user;
> Password: [PROTECTED];
> Enabled: true;
> AccountNonExpired: true;
> CredentialsNonExpired: true;
> AccountNonLocked: true;
> [  ]  is member of group(s) not administered by current user and cant be
> modified.




--
View this message in context: 
http://osgeo-org.1560.x6.nabble.com/Possible-bug-GROUP-ADMIN-deleting-users-tp5315691p5315697.html
Sent from the GeoServer - User mailing list archive at Nabble.com.

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Geoserver-users mailing list
[email protected]<mailto:[email protected]>
https://lists.sourceforge.net/lists/listinfo/geoserver-users



--
==
GeoServer Professional Services from the experts! Visit
http://goo.gl/it488V for more information.
==

Ing. Andrea Aime
@geowolf
Technical Lead

GeoSolutions S.A.S.
Via di Montramito 3/A
55054  Massarosa (LU)
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39  339 8844549

http://www.geo-solutions.it
http://twitter.com/geosolutions_it


AVVERTENZE AI SENSI DEL D.Lgs. 196/2003

Le informazioni contenute in questo messaggio di posta elettronica e/o nel/i 
file/s allegato/i sono da considerarsi strettamente riservate. Il loro utilizzo 
è consentito esclusivamente al destinatario del messaggio, per le finalità 
indicate nel messaggio stesso. Qualora riceviate questo messaggio senza esserne 
il destinatario, Vi preghiamo cortesemente di darcene notizia via e-mail e di 
procedere alla distruzione del messaggio stesso, cancellandolo dal Vostro 
sistema. Conservare il messaggio stesso, divulgarlo anche in parte, 
distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità diverse, 
costituisce comportamento contrario ai principi dettati dal D.Lgs. 196/2003.



The information in this message and/or attachments, is intended solely for the 
attention and use of the named addressee(s) and may be confidential or 
proprietary in nature or covered by the provisions of privacy act (Legislative 
Decree June, 30 2003, no.196 - Italy's New Data Protection Code).Any use not in 
accord with its purpose, any disclosure, reproduction, copying, distribution, 
or either dissemination, either whole or partial, is strictly forbidden except 
previous formal approval of the named addressee(s). If you are not the intended 
recipient, please contact immediately the sender by telephone, fax or e-mail 
and delete the information in this message that has been received in error. The 
sender does not give any warranty or accept liability as the content, accuracy 
or completeness of sent messages and accepts no responsibility  for changes 
made after they were sent or for other risks which arise as a result of e-mail 
transmission, viruses, etc.

-------------------------------------------------------

DISCLAIMER: The information contained in this communication/message from 
[email protected] sent on Tue Apr  4 17:34:04 2017 is confidential. 
It is intended solely for the addressee(s) 
[email protected];[email protected]

Access to this message by anyone else is unauthorised. If you are not the 
intended recipient, any disclosure, copying, or distribution of the message, or 
any action or omission taken by you in reliance on it, is prohibited and may be 
unlawful.
As a public body, Salford City Council may be required to disclose this email 
[or any response to it] under the Freedom of Information Act 2000, unless the 
information in it is covered by one of the exemptions in the Act. 
Please immediately contact the sender, [email protected] if you have 
received this message in error. 

For the full disclaimer please access http://www.salford.gov.uk/e-mail.  Thank 
you.
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Geoserver-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/geoserver-users

Reply via email to