Skip to content

XML connector: update of __NAME__ allows duplicate names and returns a stale uid #159

Description

@maximthomas

Found while profiling the XML connector (#157). Line references are to 1abfe74. Reproduced through ConnectorFacade with the test schemas from OpenICF-xml-connector/src/test/resources/test/xml_store, plus an object class without __UID__.

  • Duplicate names. create refuses a name that already exists (L154), but update does not check that a new __NAME__ is unique. Lookups by name then use the first entry in document order. After renaming n2 to n1, a search for n1 returns two objects, and authenticate as n1 with n2's password fails with InvalidPasswordException.
  • Stale uid. For an object class without __UID__, the uid is the __NAME__ value (L160-L164). update still returns the uid it was given (L306). After renaming d1 to d2, update returns d1, and getObject(d1) returns null.

update should apply the same uniqueness check as create when __NAME__ changes, and return the new uid when the uid is the name.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingconnector:xmlXML connector

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions