Found while profiling the XML connector (#157). Line references are to 1abfe74. Reproduced through ConnectorFacade with the test schemas from OpenICF-xml-connector/src/test/resources/test/xml_store, plus an object class without __UID__.
- Duplicate names.
create refuses a name that already exists (L154), but update does not check that a new __NAME__ is unique. Lookups by name then use the first entry in document order. After renaming n2 to n1, a search for n1 returns two objects, and authenticate as n1 with n2's password fails with InvalidPasswordException.
- Stale uid. For an object class without
__UID__, the uid is the __NAME__ value (L160-L164). update still returns the uid it was given (L306). After renaming d1 to d2, update returns d1, and getObject(d1) returns null.
update should apply the same uniqueness check as create when __NAME__ changes, and return the new uid when the uid is the name.
Found while profiling the XML connector (#157). Line references are to 1abfe74. Reproduced through
ConnectorFacadewith the test schemas fromOpenICF-xml-connector/src/test/resources/test/xml_store, plus an object class without__UID__.createrefuses a name that already exists (L154), butupdatedoes not check that a new__NAME__is unique. Lookups by name then use the first entry in document order. After renamingn2ton1, a search forn1returns two objects, andauthenticateasn1withn2's password fails withInvalidPasswordException.__UID__, the uid is the__NAME__value (L160-L164).updatestill returns the uid it was given (L306). After renamingd1tod2,updatereturnsd1, andgetObject(d1)returnsnull.updateshould apply the same uniqueness check ascreatewhen__NAME__changes, and return the new uid when the uid is the name.