[
https://issues.apache.org/jira/browse/OAK-6144?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16010291#comment-16010291
]
angela commented on OAK-6144:
-----------------------------
[~baedke], thanks for the additional info... it brings me back to another point
i mentioned above: what about the groups? if the intention of the 'active' flag
is indeed similar to the disabling of users I don't think it is sensible for
groups at all because the idea behind the 'disabled' flag was solely to prevent
users from login without having to remove the accounts. with groups that
doesn't make sense and it would IMO create a bunch of follow up questions and
ultimately troubles with the implementation. consequently, i would suggest to
move the method to {{ExternalUser}}.
regarding {{DefaultSyncContext}}: apart from the other things requested above,
may i ask you extend the patch to show the effect for {{DefaultSyncContext}}
and also for the {{DynamicSyncContext}} extension? thanks
cc: [~tripod], [~alexparvulescu]
> ExternalIdentity should have a method indicating if an identity is actually
> active
> ----------------------------------------------------------------------------------
>
> Key: OAK-6144
> URL: https://issues.apache.org/jira/browse/OAK-6144
> Project: Jackrabbit Oak
> Issue Type: New Feature
> Components: auth-external
> Reporter: Manfred Baedke
> Assignee: Manfred Baedke
> Attachments: oak-6144-1.patch
>
>
> The interface ExternalIdentityProvider currently offers the method
> getIdentity(ExternalIdentityRef) to resolve a reference to an external
> Identity, but there is no way to tell if the external identity is considered
> active by the identity provider. The ability to resolve the reference doesn't
> mean that the resulting identity may actually be used for authentication or
> authorization.
> If ExternaIIdentity isn't able to express this difference, it's hard to come
> up with a sensible implemenation of e.g.
> SynchronizationMBean#purgeOrphanedUsers(), because the ability to resolve a
> reference to an external identity doesn't mean that the corresponding Oak
> user is still valid.
> A new method ExternalIdentiy#isActive() would allow us to clearly define the
> notion of an "orphaned user".
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)