Skip to content

XML connector: a rejected update() has already removed the attribute's old values #178

Description

@maximthomas

XMLHandlerImpl.update() removes an attribute's existing values before it checks the new ones, so an update that is rejected still changes the entry.

Where

OpenICF-xml-connector/src/main/java/org/forgerock/openicf/connectors/xml/XMLHandlerImpl.java, update(), on master: inside the loop over replaceAttributes, removeChildrenFromElement(entry, …) runs at line 280, and the single-valued check if (!attributeInfo.isMultiValued() && values.size() > 1) throw new IllegalArgumentException(…) runs after it, at line 285.

Scenario

update(ACCOUNT, uid-alice, {lastname = ["A", "B"]}), where lastname is single-valued, throws IllegalArgumentException: Data field: lastname is not multivalued can not have more than one value, but alice's lastname has already been removed from the document. On master dispose() saves after every call, so the removal also reaches the file.

The same happens across attributes. update() checks each attribute just before it replaces it, so when a later attribute is rejected (not supported, not updatable, a missing or blank required value, values of the wrong type, or the single-valued rule), the attributes before it in the set have already been replaced.

Expected

An update that throws leaves the entry as it was: check every attribute in replaceAttributes (supported, updatable, required values, value types, the single-valued rule) before the first change, as create() checks every attribute before it appends the new entry.

Notes

Activity

  1. added
    bugSomething isn't working
    javaPull requests that update java code
    data-lossFixes or risks loss or corruption of stored data
    on Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingconnector:xmlXML connectordata-lossFixes or risks loss or corruption of stored datajavaPull requests that update java code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions