From 6887e980c48e45a5ae22642932ed22e0c8b5f665 Mon Sep 17 00:00:00 2001 From: Viliam Repan Date: Tue, 5 Sep 2023 11:43:34 +0200 Subject: [PATCH] updated initial objects, mostly added container ids --- .../archetype/020-archetype-system-user.xml | 4 +- .../archetype/021-archetype-system-role.xml | 4 +- .../archetype/022-archetype-business-role.xml | 4 +- ...023-archetype-manual-provisioning-case.xml | 8 +- .../024-archetype-operation-request.xml | 8 +- .../archetype/025-archetype-approval-case.xml | 8 +- .../027-archetype-correlation-case.xml | 8 +- .../028-archetype-application-role.xml | 4 +- .../archetype/029-archetype-application.xml | 28 +- .../archetype/059-archetype-report.xml | 20 +- .../060-archetype-report-dashboard.xml | 20 +- .../061-archetype-report-collection.xml | 24 +- .../501-archetype-task-reconciliation.xml | 80 +- .../502-archetype-task-recomputation.xml | 78 +- .../archetype/503-archetype-task-import.xml | 80 +- .../504-archetype-task-live-sync.xml | 88 +- .../505-archetype-task-async-update.xml | 62 +- .../archetype/506-archetype-task-cleanup.xml | 56 +- .../archetype/507-archetype-task-report.xml | 18 +- .../508-archetype-task-single-bulk-action.xml | 56 +- ...9-archetype-task-iterative-bulk-action.xml | 78 +- ...0-archetype-task-report-import-classic.xml | 12 +- ...1-archetype-task-report-export-classic.xml | 8 +- ...chetype-task-report-export-distributed.xml | 8 +- ...-archetype-task-shadow-integrity-check.xml | 76 +- .../514-archetype-task-shadows-refresh.xml | 60 +- .../515-archetype-task-objects-delete.xml | 58 +- ...k-shadows-delete-long-time-not-updated.xml | 64 +- .../517-archetype-task-execute-change.xml | 66 +- .../518-archetype-task-execute-deltas.xml | 54 +- .../519-archetype-task-reindex-repository.xml | 60 +- .../520-archetype-task-certification.xml | 21 +- .../archetype/521-archetype-task-approval.xml | 25 +- ...-archetype-task-object-integrity-check.xml | 62 +- .../archetype/528-archetype-task-util.xml | 17 +- .../archetype/529-archetype-task-system.xml | 17 +- .../archetype/530-archetype-task-validity.xml | 64 +- .../archetype/531-archetype-task-trigger.xml | 64 +- .../532-archetype-task-propagation.xml | 46 +- .../533-archetype-task-multi-propagation.xml | 27 +- .../archetype/700-archetype-event-mark.xml | 4 +- .../archetype/701-archetype-object-mark.xml | 8 +- .../archetype/702-archetype-person.xml | 29 + .../dashboard/310-dashboard-admin.xml | 32 +- .../lookup-table/200-lookup-languages.xml | 36 +- .../lookup-table/210-lookup-locales.xml | 39 +- .../lookup-table/220-lookup-timezones.xml | 839 +++++++++--------- .../230-lookup-lifecycle-state.xml | 25 +- .../lookup-table/240-lookup-state.xml | 15 +- .../mark/710-mark-focus-activated.xml | 6 +- .../mark/711-mark-focus-deactivated.xml | 6 +- .../mark/712-mark-focus-renamed.xml | 6 +- .../713-mark-focus-assignment-changed.xml | 6 +- .../mark/714-mark-focus-archetype-changed.xml | 6 +- ...ark-focus-parent-org-reference-changed.xml | 6 +- ...716-mark-focus-role-membership-changed.xml | 6 +- .../mark/730-mark-projection-activated.xml | 6 +- .../mark/731-mark-projection-deactivated.xml | 6 +- .../mark/732-mark-projection-renamed.xml | 6 +- ...733-mark-projection-identifier-changed.xml | 6 +- ...34-mark-projection-entitlement-changed.xml | 6 +- .../735-mark-projection-password-changed.xml | 6 +- ...736-mark-shadow-classification-changed.xml | 2 +- ...-mark-shadow-correlation-state-changed.xml | 2 +- ...rk-projection-resource-object-affected.xml | 10 +- .../mark/800-mark-protected.xml | 2 +- .../mark/801-mark-decommission-later.xml | 2 +- .../mark/802-mark-correlate-later.xml | 2 +- .../mark/803-mark-do-not-touch.xml | 2 +- .../mark/804-mark-invalid-data.xml | 2 +- .../251-object-collection-resource-up.xml | 6 +- .../261-object-collection-task-active.xml | 6 +- .../270-object-collection-audit.xml | 16 +- ...-collection-certification-campaign-all.xml | 2 +- .../290-object-collection-shadow-all.xml | 2 +- .../380-object-template-person.xml | 104 +++ .../report/090-report-audit.xml | 16 +- .../report/100-report-reconciliation.xml | 22 +- .../report/110-report-user-list.xml | 22 +- .../130-report-certification-definitions.xml | 16 +- .../140-report-certification-campaigns.xml | 22 +- .../report/150-report-certification-cases.xml | 26 +- .../160-report-certification-work-items.xml | 38 +- .../report/170-report-simulation-objects.xml | 34 +- ...report-simulation-objects-with-metrics.xml | 44 +- .../172-report-simulation-items-changed.xml | 70 +- .../173-report-simulation-values-changed.xml | 68 +- .../report/180-report-simulation-results.xml | 48 +- .../200-report-indirect-assignments.xml | 28 +- .../role/030-role-superuser.xml | 4 +- .../initial-objects/role/040-role-enduser.xml | 82 +- .../role/041-role-approver.xml | 26 +- .../role/042-role-reviewer.xml | 22 +- .../role/043-role-delegator.xml | 26 +- .../security-policy/015-security-policy.xml | 16 +- .../service/610-service-identity-recovery.xml | 2 +- .../000-system-configuration.xml | 561 ++++++------ .../initial-objects/task/550-task-cleanup.xml | 2 +- .../task/560-task-validity.xml | 4 +- .../initial-objects/task/570-task-trigger.xml | 4 +- .../user/050-user-administrator.xml | 4 +- 101 files changed, 1771 insertions(+), 2246 deletions(-) create mode 100644 config/initial-objects/archetype/702-archetype-person.xml create mode 100644 config/initial-objects/object-templates/380-object-template-person.xml diff --git a/config/initial-objects/archetype/020-archetype-system-user.xml b/config/initial-objects/archetype/020-archetype-system-user.xml index 41c57fd8bdb..fa0f1a88682 100644 --- a/config/initial-objects/archetype/020-archetype-system-user.xml +++ b/config/initial-objects/archetype/020-archetype-system-user.xml @@ -24,8 +24,8 @@ - - + + UserType diff --git a/config/initial-objects/archetype/021-archetype-system-role.xml b/config/initial-objects/archetype/021-archetype-system-role.xml index ec1d7926fc9..d4181cba995 100644 --- a/config/initial-objects/archetype/021-archetype-system-role.xml +++ b/config/initial-objects/archetype/021-archetype-system-role.xml @@ -26,8 +26,8 @@ - - + + RoleType diff --git a/config/initial-objects/archetype/022-archetype-business-role.xml b/config/initial-objects/archetype/022-archetype-business-role.xml index 39d97eec76f..9d6fab40da7 100644 --- a/config/initial-objects/archetype/022-archetype-business-role.xml +++ b/config/initial-objects/archetype/022-archetype-business-role.xml @@ -43,8 +43,8 @@ - - + + RoleType diff --git a/config/initial-objects/archetype/023-archetype-manual-provisioning-case.xml b/config/initial-objects/archetype/023-archetype-manual-provisioning-case.xml index 8749a51ed33..5c5c05c38c6 100644 --- a/config/initial-objects/archetype/023-archetype-manual-provisioning-case.xml +++ b/config/initial-objects/archetype/023-archetype-manual-provisioning-case.xml @@ -23,7 +23,7 @@ - + manualCase @@ -34,7 +34,7 @@ manualCase c:CaseType - + caseWorkItems @@ -48,8 +48,8 @@ - - + + CaseType diff --git a/config/initial-objects/archetype/024-archetype-operation-request.xml b/config/initial-objects/archetype/024-archetype-operation-request.xml index 3c4b15f586c..840836fe502 100644 --- a/config/initial-objects/archetype/024-archetype-operation-request.xml +++ b/config/initial-objects/archetype/024-archetype-operation-request.xml @@ -23,7 +23,7 @@ - + childCases @@ -34,7 +34,7 @@ childCases c:CaseType - + operationRequestCase @@ -50,8 +50,8 @@ - - + + CaseType diff --git a/config/initial-objects/archetype/025-archetype-approval-case.xml b/config/initial-objects/archetype/025-archetype-approval-case.xml index 72b1de6a200..00afed22489 100644 --- a/config/initial-objects/archetype/025-archetype-approval-case.xml +++ b/config/initial-objects/archetype/025-archetype-approval-case.xml @@ -23,7 +23,7 @@ - + caseWorkItems @@ -34,7 +34,7 @@ caseWorkItems c:CaseType - + approvalCase @@ -50,8 +50,8 @@ - - + + CaseType diff --git a/config/initial-objects/archetype/027-archetype-correlation-case.xml b/config/initial-objects/archetype/027-archetype-correlation-case.xml index dc265fd443a..4a92e5225e4 100644 --- a/config/initial-objects/archetype/027-archetype-correlation-case.xml +++ b/config/initial-objects/archetype/027-archetype-correlation-case.xml @@ -21,7 +21,7 @@ - + caseWorkItems @@ -33,7 +33,7 @@ caseWorkItems c:CaseType - + correlationContext @@ -49,8 +49,8 @@ - - + + CaseType diff --git a/config/initial-objects/archetype/028-archetype-application-role.xml b/config/initial-objects/archetype/028-archetype-application-role.xml index cf71620e453..a0201c9979c 100644 --- a/config/initial-objects/archetype/028-archetype-application-role.xml +++ b/config/initial-objects/archetype/028-archetype-application-role.xml @@ -26,8 +26,8 @@ - - + + RoleType diff --git a/config/initial-objects/archetype/029-archetype-application.xml b/config/initial-objects/archetype/029-archetype-application.xml index bd84bbcb22c..1a16fbde6b9 100644 --- a/config/initial-objects/archetype/029-archetype-application.xml +++ b/config/initial-objects/archetype/029-archetype-application.xml @@ -25,26 +25,26 @@ - + projections projections - + assignments hidden - + password hidden - + applicablePolicies hidden - + serviceMembers @@ -59,11 +59,11 @@ - + serviceGovernance hidden - + governance @@ -74,11 +74,11 @@ 91 governanceCards - + inducements hidden - + resourceEntitlementsTopLevel constructionInducements @@ -86,7 +86,7 @@ 115 - + inducedEntitlementsTopLevel inducedEntitlements @@ -94,7 +94,7 @@ 116 - + applicationRoles inducedBy @@ -116,7 +116,7 @@ 117 - + inducedBy inducedBy 118 @@ -124,8 +124,8 @@ - - + + ServiceType diff --git a/config/initial-objects/archetype/059-archetype-report.xml b/config/initial-objects/archetype/059-archetype-report.xml index e4f92ee0149..4796f3d953b 100644 --- a/config/initial-objects/archetype/059-archetype-report.xml +++ b/config/initial-objects/archetype/059-archetype-report.xml @@ -20,35 +20,35 @@ #001F3F - + jasper hidden - + diagnosticInformation hidden - + defaultScriptConfiguration hidden - + postReportScript hidden - + lifecycleState hidden ReportType - + assignments hidden assignments - + fileFormat 20 @@ -58,7 +58,7 @@ fas fa-file-alt - + fileFormat formPanel @@ -68,8 +68,8 @@ - - + + ReportType diff --git a/config/initial-objects/archetype/060-archetype-report-dashboard.xml b/config/initial-objects/archetype/060-archetype-report-dashboard.xml index fcb1fa6b21c..9e5886f3e9d 100644 --- a/config/initial-objects/archetype/060-archetype-report-dashboard.xml +++ b/config/initial-objects/archetype/060-archetype-report-dashboard.xml @@ -23,14 +23,14 @@ #001F3F - + objectCollection hidden ReportType - + engine 11 @@ -40,18 +40,18 @@ fa fa-microchip - + engineContainer - + dashboard/dashboardRef - + dashboard/showOnlyWidgetsTable - + dashboard/storeExportedWidgetData @@ -59,7 +59,7 @@ c:dashboard c:DashboardReportEngineConfigurationType - + view @@ -68,7 +68,7 @@ fa fa-eye - + dashboard @@ -82,8 +82,8 @@ - - + + ReportType diff --git a/config/initial-objects/archetype/061-archetype-report-collection.xml b/config/initial-objects/archetype/061-archetype-report-collection.xml index d55bbd869fc..7bdf8920e7d 100644 --- a/config/initial-objects/archetype/061-archetype-report-collection.xml +++ b/config/initial-objects/archetype/061-archetype-report-collection.xml @@ -23,14 +23,14 @@ #001F3F - + dashboard hidden ReportType - + engine 11 @@ -40,15 +40,15 @@ fa fa-microchip - + engineContainer - + objectCollection/condition - + objectCollection/useOnlyReportView @@ -56,7 +56,7 @@ c:objectCollection c:ObjectCollectionReportEngineConfigurationType - + collection 12 @@ -66,14 +66,14 @@ fa fa-filter - + objectCollection/collection formPanel c:objectCollection/collection c:CollectionRefSpecificationType - + view @@ -84,7 +84,7 @@ reportCollectionView - + parameters @@ -95,7 +95,7 @@ reportCollectionParameter - + subreport @@ -109,8 +109,8 @@ - - + + ReportType diff --git a/config/initial-objects/archetype/501-archetype-task-reconciliation.xml b/config/initial-objects/archetype/501-archetype-task-reconciliation.xml index 929e47da40b..a46c07baa12 100644 --- a/config/initial-objects/archetype/501-archetype-task-reconciliation.xml +++ b/config/initial-objects/archetype/501-archetype-task-reconciliation.xml @@ -23,79 +23,79 @@ green - + extension vacant - + extension/mext:objectclass visible - + extension/mext:kind visible - + extension/mext:intent visible - + extension/mext:objectQuery visible - + extension/mext:workerThreads visible - + extension/mext:dryRun visible c:TaskType - + activity - + work - + work-reconciliation activity/work/reconciliation - + taskBasic - + resource-objects - + objectRef - + extension/mext:objectclass - + extension/mext:kind - + extension/mext:intent - + extension/mext:objectQuery - + reconciliation-options - + extension/mext:workerThreads - + extension/mext:dryRun @@ -103,14 +103,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/502-archetype-task-recomputation.xml b/config/initial-objects/archetype/502-archetype-task-recomputation.xml index 3b63d72c573..f7bc4de0209 100644 --- a/config/initial-objects/archetype/502-archetype-task-recomputation.xml +++ b/config/initial-objects/archetype/502-archetype-task-recomputation.xml @@ -23,76 +23,76 @@ green - + extension vacant - + extension/mext:objectType visible - + extension/mext:objectQuery visible - + extension/mext:searchOptions visible - + extension/mext:useRepositoryDirectly visible - + extension/mext:workerThreads visible - + extension/mext:modelExecuteOptions visible c:TaskType - + activity - + work - + work-recomputation activity/work/recomputation - + taskBasic - + objects-to-recompute - + extension/mext:objectType - + extension/mext:objectQuery - + extension/mext:searchOptions - + extension/mext:useRepositoryDirectly - + recompute-options - + extension/mext:workerThreads - + extension/mext:modelExecuteOptions @@ -100,14 +100,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/503-archetype-task-import.xml b/config/initial-objects/archetype/503-archetype-task-import.xml index 54bd7b60650..89814a797b4 100644 --- a/config/initial-objects/archetype/503-archetype-task-import.xml +++ b/config/initial-objects/archetype/503-archetype-task-import.xml @@ -23,79 +23,79 @@ green - + extension vacant - + extension/mext:objectclass visible - + extension/mext:kind visible - + extension/mext:intent visible - + extension/mext:objectQuery visible - + extension/mext:workerThreads visible - + extension/mext:dryRun visible TaskType - + activity - + work - + work-import activity/work/import - + taskBasic - + objects-to-import - + objectRef - + extension/mext:objectclass - + extension/mext:kind - + extension/mext:intent - + extension/mext:objectQuery - + import-options - + extension/mext:workerThreads - + extension/mext:dryRun @@ -103,14 +103,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/504-archetype-task-live-sync.xml b/config/initial-objects/archetype/504-archetype-task-live-sync.xml index e00441b93e8..e7eaa6db4c0 100644 --- a/config/initial-objects/archetype/504-archetype-task-live-sync.xml +++ b/config/initial-objects/archetype/504-archetype-task-live-sync.xml @@ -24,94 +24,94 @@ green - + extension vacant - + extension/mext:objectclass visible - + extension/mext:kind visible - + extension/mext:intent visible - + extension/mext:synchronizationOptions visible - + extension/mext:workerThreads visible - + extension/mext:dryRun visible - + extension/mext:retryLiveSyncErrors visible - + extension/mext:updateLiveSyncTokenInDryRun visible - + extension/livesync:token visible TaskType - + activity - + work - + work-live-sync activity/work/liveSynchronization - + taskBasic - + objects-to-synchronize - + objectRef - + extension/mext:objectclass - + extension/mext:kind - + extension/mext:intent - + synchronization-options - + extension/mext:workerThreads - + extension/mext:dryRun - + extension/mext:retryLiveSyncErrors - + extension/mext:updateLiveSyncTokenInDryRun @@ -119,14 +119,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/505-archetype-task-async-update.xml b/config/initial-objects/archetype/505-archetype-task-async-update.xml index e37268e7129..4495f4d89d1 100644 --- a/config/initial-objects/archetype/505-archetype-task-async-update.xml +++ b/config/initial-objects/archetype/505-archetype-task-async-update.xml @@ -23,38 +23,38 @@ green - + extension vacant - - extension/mext:workerThreads + + extension/mext:workerThreads visible TaskType - + activity - + work - + work-asynchronous-update activity/work/asynchronousUpdate - + taskBasic - + async-options - - objectRef + + objectRef - + extension/mext:workerThreads @@ -62,14 +62,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/506-archetype-task-cleanup.xml b/config/initial-objects/archetype/506-archetype-task-cleanup.xml index f939de01c91..2998778761b 100644 --- a/config/initial-objects/archetype/506-archetype-task-cleanup.xml +++ b/config/initial-objects/archetype/506-archetype-task-cleanup.xml @@ -23,35 +23,35 @@ green - + extension vacant - + extension/mext:cleanupPolicies visible TaskType - + activity - + work - + work-cleanup activity/work/cleanup - + taskBasic - + cleanup-options - + extension/mext:cleanupPolicies @@ -59,14 +59,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/507-archetype-task-report.xml b/config/initial-objects/archetype/507-archetype-task-report.xml index 558d07be1c9..d8ffb253c1c 100644 --- a/config/initial-objects/archetype/507-archetype-task-report.xml +++ b/config/initial-objects/archetype/507-archetype-task-report.xml @@ -24,32 +24,32 @@ green - + extension vacant - + extension/rext:reportParam visible - + extension/rext:reportDataParam visible TaskType - + taskBasic - + report-options - + extension/rext:reportParam - + extension/rext:reportDataParam @@ -57,8 +57,8 @@ - - + + TaskType diff --git a/config/initial-objects/archetype/508-archetype-task-single-bulk-action.xml b/config/initial-objects/archetype/508-archetype-task-single-bulk-action.xml index 228aade8fbd..b37ef48e33e 100644 --- a/config/initial-objects/archetype/508-archetype-task-single-bulk-action.xml +++ b/config/initial-objects/archetype/508-archetype-task-single-bulk-action.xml @@ -23,35 +23,35 @@ green - + extension vacant - + extension/scext:executeScript visible TaskType - + activity - + work - + work-noniterative-scripting activity/work/nonIterativeScripting - + taskBasic - + bulk-action - + extension/scext:executeScript @@ -59,14 +59,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/509-archetype-task-iterative-bulk-action.xml b/config/initial-objects/archetype/509-archetype-task-iterative-bulk-action.xml index 501c1ada3b8..447c5252569 100644 --- a/config/initial-objects/archetype/509-archetype-task-iterative-bulk-action.xml +++ b/config/initial-objects/archetype/509-archetype-task-iterative-bulk-action.xml @@ -24,76 +24,76 @@ green - + extension vacant - + extension/mext:objectType visible - + extension/mext:objectQuery visible - + extension/mext:searchOptions visible - + extension/mext:useRepositoryDirectly visible - + extension/scext:executeScript visible - + extension/mext:workerThreads visible c:TaskType - + activity - + work - + work-iterative-scripting activity/work/iterativeScripting - + taskBasic - + objects-to-process - + extension/mext:objectType - + extension/mext:objectQuery - + extension/mext:searchOptions - + extension/mext:useRepositoryDirectly - + bulk-action - + extension/scext:executeScript - + extension/mext:workerThreads @@ -101,14 +101,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/510-archetype-task-report-import-classic.xml b/config/initial-objects/archetype/510-archetype-task-report-import-classic.xml index 06a66cbaa76..599ed01b680 100644 --- a/config/initial-objects/archetype/510-archetype-task-report-import-classic.xml +++ b/config/initial-objects/archetype/510-archetype-task-report-import-classic.xml @@ -23,18 +23,18 @@ green - + extension/rext:reportParam hidden TaskType - + activity - + work - + activity/work/reportImport @@ -42,8 +42,8 @@ - - + + TaskType diff --git a/config/initial-objects/archetype/511-archetype-task-report-export-classic.xml b/config/initial-objects/archetype/511-archetype-task-report-export-classic.xml index 08bdeca4844..7e9c9495603 100644 --- a/config/initial-objects/archetype/511-archetype-task-report-export-classic.xml +++ b/config/initial-objects/archetype/511-archetype-task-report-export-classic.xml @@ -26,14 +26,14 @@ TaskType - + activity - + work - + activity/work/reportExport - + diff --git a/config/initial-objects/archetype/512-archetype-task-report-export-distributed.xml b/config/initial-objects/archetype/512-archetype-task-report-export-distributed.xml index fbf7755a426..409ea3573ec 100644 --- a/config/initial-objects/archetype/512-archetype-task-report-export-distributed.xml +++ b/config/initial-objects/archetype/512-archetype-task-report-export-distributed.xml @@ -25,14 +25,14 @@ TaskType - + activity - + work - + activity/work/distributedReportExport - + diff --git a/config/initial-objects/archetype/513-archetype-task-shadow-integrity-check.xml b/config/initial-objects/archetype/513-archetype-task-shadow-integrity-check.xml index d27e53fee8e..60213e872c8 100644 --- a/config/initial-objects/archetype/513-archetype-task-shadow-integrity-check.xml +++ b/config/initial-objects/archetype/513-archetype-task-shadow-integrity-check.xml @@ -24,66 +24,66 @@ green - + extension vacant - + extension/mext:objectType hidden - + extension/mext:objectQuery visible - + extension/mext:searchOptions visible - + extension/mext:iterationMethod visible - + extension/mext:useRepositoryDirectly visible - + extension/mext:failedObjectsSelector visible - + extension/mext:workerThreads visible - + extension/mext:dryRun visible - + extension/mext:diagnose visible - + extension/mext:fix visible - + extension/mext:duplicateShadowsResolver visible - + extension/mext:checkDuplicatesOnPrimaryIdentifiersOnly visible TaskType - + activity - + work - + work-shadowIntegrityCheck activity/work/shadowIntegrityCheck @@ -92,14 +92,14 @@ - - + + TaskType - + - + weak - - - - diff --git a/config/initial-objects/archetype/514-archetype-task-shadows-refresh.xml b/config/initial-objects/archetype/514-archetype-task-shadows-refresh.xml index 11f863f81df..01a1f25f694 100644 --- a/config/initial-objects/archetype/514-archetype-task-shadows-refresh.xml +++ b/config/initial-objects/archetype/514-archetype-task-shadows-refresh.xml @@ -24,42 +24,42 @@ green - + extension vacant - + extension/mext:objectType visible - + extension/mext:objectQuery visible - + extension/mext:searchOptions visible - + extension/mext:iterationMethod visible - + extension/mext:useRepositoryDirectly visible - + extension/mext:failedObjectsSelector visible TaskType - + activity - + work - + work-shadowRefresh activity/work/shadowRefresh @@ -68,14 +68,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/515-archetype-task-objects-delete.xml b/config/initial-objects/archetype/515-archetype-task-objects-delete.xml index 0f867c6a50e..964387c091c 100644 --- a/config/initial-objects/archetype/515-archetype-task-objects-delete.xml +++ b/config/initial-objects/archetype/515-archetype-task-objects-delete.xml @@ -24,38 +24,38 @@ green - + extension vacant - + extension/mext:optionRaw visible - + extension/mext:objectType visible - + extension/mext:objectQuery visible - + extension/mext:useRepositoryDirectly visible - + extension/mext:failedObjectsSelector visible TaskType - + activity - + work - + work-deletion activity/work/deletion @@ -64,14 +64,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/516-archetype-task-shadows-delete-long-time-not-updated.xml b/config/initial-objects/archetype/516-archetype-task-shadows-delete-long-time-not-updated.xml index 580cce12d1e..aed4444bedb 100644 --- a/config/initial-objects/archetype/516-archetype-task-shadows-delete-long-time-not-updated.xml +++ b/config/initial-objects/archetype/516-archetype-task-shadows-delete-long-time-not-updated.xml @@ -24,50 +24,50 @@ green - + extension vacant - + extension/mext:objectclass visible - + extension/mext:kind visible - + extension/mext:intent visible - + extension/mext:objectQuery visible - + extension/mext:searchOptions visible - + extension/mext:iterationMethod visible - + extension/mext:failedObjectsSelector visible - + extension/mext:notUpdatedShadowsDuration visible TaskType - + activity - + work - + work-shadowCleanup activity/work/shadowCleanup @@ -76,14 +76,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/517-archetype-task-execute-change.xml b/config/initial-objects/archetype/517-archetype-task-execute-change.xml index 0d8c98f66dd..84f364c3cae 100644 --- a/config/initial-objects/archetype/517-archetype-task-execute-change.xml +++ b/config/initial-objects/archetype/517-archetype-task-execute-change.xml @@ -24,54 +24,54 @@ green - + extension vacant - + extension/mext:objectType visible - + extension/mext:objectQuery visible - + extension/mext:searchOptions visible - + extension/mext:iterationMethod visible - + extension/mext:useRepositoryDirectly visible - + extension/mext:failedObjectsSelector visible - + extension/mext:workerThreads visible - + extension/mext:objectDelta visible - + extension/mext:modelExecuteOptions visible TaskType - + activity - + work - + work-iterativeChangeExecution activity/work/iterativeChangeExecution @@ -80,14 +80,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/518-archetype-task-execute-deltas.xml b/config/initial-objects/archetype/518-archetype-task-execute-deltas.xml index a0dfd43332b..6e2bcf20f31 100644 --- a/config/initial-objects/archetype/518-archetype-task-execute-deltas.xml +++ b/config/initial-objects/archetype/518-archetype-task-execute-deltas.xml @@ -10,14 +10,14 @@ xmlns:t="http://prism.evolveum.com/xml/ns/public/types-3" xmlns:mext="http://midpoint.evolveum.com/xml/ns/public/model/extension-3"> Execute deltas task (background processing for change execution) - - + + TaskType - + - + weak - - @@ -78,30 +46,30 @@ green - + extension vacant - + extension/mext:objectDeltas visible - + extension/mext:objectDelta visible - + extension/mext:modelExecuteOptions visible TaskType - + activity - + work - + work-explicitChangeExecution activity/work/explicitChangeExecution diff --git a/config/initial-objects/archetype/519-archetype-task-reindex-repository.xml b/config/initial-objects/archetype/519-archetype-task-reindex-repository.xml index 5d49f5867b0..2e3ffd2b5b4 100644 --- a/config/initial-objects/archetype/519-archetype-task-reindex-repository.xml +++ b/config/initial-objects/archetype/519-archetype-task-reindex-repository.xml @@ -24,42 +24,42 @@ green - + extension vacant - + extension/mext:objectType visible - + extension/mext:objectQuery visible - + extension/mext:searchOptions visible - + extension/mext:iterationMethod visible - + extension/mext:useRepositoryDirectly visible - + extension/mext:failedObjectsSelector visible TaskType - + activity - + work - + work-reindexing activity/work/reindexing @@ -68,14 +68,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/520-archetype-task-certification.xml b/config/initial-objects/archetype/520-archetype-task-certification.xml index e24262a47c4..1db16e1e37e 100644 --- a/config/initial-objects/archetype/520-archetype-task-certification.xml +++ b/config/initial-objects/archetype/520-archetype-task-certification.xml @@ -26,25 +26,25 @@ TaskType - + activity hidden - + taskBasic true - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/528-archetype-task-util.xml b/config/initial-objects/archetype/528-archetype-task-util.xml index abec8fa276c..a1884266490 100644 --- a/config/initial-objects/archetype/528-archetype-task-util.xml +++ b/config/initial-objects/archetype/528-archetype-task-util.xml @@ -24,22 +24,9 @@ - - + + TaskType - - - - weak - - Utility - - - category - - - - diff --git a/config/initial-objects/archetype/529-archetype-task-system.xml b/config/initial-objects/archetype/529-archetype-task-system.xml index 8cf2140021a..70d7a8e0cf9 100644 --- a/config/initial-objects/archetype/529-archetype-task-system.xml +++ b/config/initial-objects/archetype/529-archetype-task-system.xml @@ -24,22 +24,9 @@ - - + + TaskType - - - - weak - - System - - - category - - - - diff --git a/config/initial-objects/archetype/530-archetype-task-validity.xml b/config/initial-objects/archetype/530-archetype-task-validity.xml index 9cd8fabfa5c..0aca1c45c6d 100644 --- a/config/initial-objects/archetype/530-archetype-task-validity.xml +++ b/config/initial-objects/archetype/530-archetype-task-validity.xml @@ -24,50 +24,50 @@ green - + extension vacant - + extension/mext:objectType visible - + extension/mext:objectQuery visible - + extension/mext:searchOptions visible - + extension/mext:iterationMethod visible - + extension/mext:useRepositoryDirectly visible - + extension/mext:failedObjectsSelector visible - + extension/mext:workerThreads visible - + extension/mext:lastScanTimestamp visible TaskType - + activity - + work - + work-focusValidityScan activity/work/focusValidityScan @@ -76,14 +76,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/531-archetype-task-trigger.xml b/config/initial-objects/archetype/531-archetype-task-trigger.xml index dd671fa1adf..f35eb0f2f60 100644 --- a/config/initial-objects/archetype/531-archetype-task-trigger.xml +++ b/config/initial-objects/archetype/531-archetype-task-trigger.xml @@ -24,50 +24,50 @@ green - + extension vacant - + extension/mext:objectType visible - + extension/mext:objectQuery visible - + extension/mext:searchOptions visible - + extension/mext:iterationMethod visible - + extension/mext:useRepositoryDirectly visible - + extension/mext:failedObjectsSelector visible - + extension/mext:workerThreads visible - + extension/mext:lastScanTimestamp visible TaskType - + activity - + work - + work-triggerScan activity/work/triggerScan @@ -76,14 +76,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/532-archetype-task-propagation.xml b/config/initial-objects/archetype/532-archetype-task-propagation.xml index 7fc3c67e73e..dea93e3718e 100644 --- a/config/initial-objects/archetype/532-archetype-task-propagation.xml +++ b/config/initial-objects/archetype/532-archetype-task-propagation.xml @@ -26,11 +26,11 @@ TaskType - + activity - + work - + work-propagation activity/work/propagation @@ -39,14 +39,14 @@ - - + + TaskType - + - + weak - - diff --git a/config/initial-objects/archetype/533-archetype-task-multi-propagation.xml b/config/initial-objects/archetype/533-archetype-task-multi-propagation.xml index 58ac437c708..8b6b21d5e59 100644 --- a/config/initial-objects/archetype/533-archetype-task-multi-propagation.xml +++ b/config/initial-objects/archetype/533-archetype-task-multi-propagation.xml @@ -26,11 +26,11 @@ TaskType - + activity - + work - + work-multiPropagation activity/work/multiPropagation @@ -39,14 +39,14 @@ - - + + TaskType - + - + weak - + - + - + + + + + Generate unique name for users using jsmith and iterator suitable for sAMAccountName (8 + up to 2 characters) + Generate login name - only once. Does not change the login name when user is renamed. Example: John Smith-Baker, jsmithba or jsmithba2 + + Generate a login based on "jsmith" convention. Maximum length of login is 10 characters (8 + up-to 2-digit iterator). + + If the login is not unique, a number 2-99 is appended. + + Example: + + * First name: Juan-Carlos + * Last name: de la Garcia + * Returns: jdelagar (normalized, spaces trimmed, shortened to 8) + + This algorithm can be further improved, e.g. to remove "von", "von der", "van", "van der", "de la" from lastName before doing normalization. + + draft + weak + + givenName + + + familyName + + + + + + name + + + + Generate fullName + Generate fullName (enforcing on renames because of strong mapping) + strong + + givenName + + + familyName + + + + + + fullName + + + diff --git a/config/initial-objects/report/090-report-audit.xml b/config/initial-objects/report/090-report-audit.xml index a7fc1a3666d..eded47614bf 100644 --- a/config/initial-objects/report/090-report-audit.xml +++ b/config/initial-objects/report/090-report-audit.xml @@ -12,7 +12,7 @@ oid="00000000-0000-0000-0000-000000000080"> All audit records report Report made from all audit records. - + @@ -74,7 +74,7 @@ - + outcome OperationResultStatusType @@ -86,7 +86,7 @@ - + eventType AuditEventTypeType @@ -98,7 +98,7 @@ - + eventStage AuditEventStageType @@ -110,7 +110,7 @@ - + from dateTime @@ -122,7 +122,7 @@ - + to dateTime @@ -134,7 +134,7 @@ - + targetRef c:ObjectReferenceType @@ -146,7 +146,7 @@ - + initiatorRef c:ObjectReferenceType diff --git a/config/initial-objects/report/100-report-reconciliation.xml b/config/initial-objects/report/100-report-reconciliation.xml index 27f672ce144..1f9c583f249 100644 --- a/config/initial-objects/report/100-report-reconciliation.xml +++ b/config/initial-objects/report/100-report-reconciliation.xml @@ -12,7 +12,7 @@ oid="00000000-0000-0000-0000-000000000100"> Reconciliation report Reconciliation report for selected resource. - + @@ -66,7 +66,7 @@ - + intent string @@ -78,7 +78,7 @@ - + objectClass string @@ -90,7 +90,7 @@ - + kind ShadowKindType @@ -102,7 +102,7 @@ - + situation SynchronizationSituationType @@ -114,7 +114,7 @@ - + resourceRef c:ObjectReferenceType c:ResourceType @@ -129,21 +129,21 @@ ShadowType - + nameColumn name - + resourceColumn resourceRef nameColumn - + situationColumn synchronizationSituation resourceColumn - + ownerColumn @@ -169,7 +169,7 @@ situationColumn - + synchTimestampColumn synchronizationTimestamp ownerColumn diff --git a/config/initial-objects/report/110-report-user-list.xml b/config/initial-objects/report/110-report-user-list.xml index 0630e1bf4a1..ab2c83a6d79 100644 --- a/config/initial-objects/report/110-report-user-list.xml +++ b/config/initial-objects/report/110-report-user-list.xml @@ -12,7 +12,7 @@ oid="00000000-0000-0000-0000-000000000110"> Users in MidPoint Users listed in MidPoint. - + @@ -50,7 +50,7 @@ - + activation ActivationStatusType @@ -62,7 +62,7 @@ - + organizationRef c:ObjectReferenceType c:OrgType @@ -75,7 +75,7 @@ - + roleRef c:ObjectReferenceType c:RoleType @@ -88,7 +88,7 @@ - + resourceRef c:ObjectReferenceType c:ResourceType @@ -102,21 +102,21 @@ - + nameColumn name - + fullNameColumn fullName nameColumn - + activationColumn activation/administrativeStatus fullNameColumn - + roleColumn assignment @@ -143,7 +143,7 @@ activationColumn - + orgColumn assignment @@ -170,7 +170,7 @@ roleColumn - + accountColumn linkRef diff --git a/config/initial-objects/report/130-report-certification-definitions.xml b/config/initial-objects/report/130-report-certification-definitions.xml index f93024e9050..c2800decef3 100644 --- a/config/initial-objects/report/130-report-certification-definitions.xml +++ b/config/initial-objects/report/130-report-certification-definitions.xml @@ -11,7 +11,7 @@ oid="00000000-0000-0000-0000-000000000130"> Certification definitions report All certification definitions with basic information on related campaigns. - + @@ -21,11 +21,11 @@ - + name name - + owner ownerRef @@ -33,7 +33,7 @@ name - + campaigns @@ -48,7 +48,7 @@ number - + openCampaigns @@ -68,7 +68,7 @@ - + lastStarted lastCampaignStartedTimestamp @@ -76,7 +76,7 @@ openCampaigns - + lastClosed lastCampaignClosedTimestamp @@ -91,7 +91,7 @@ AccessCertificationDefinitionType true - + campaigns AccessCertificationCampaignType diff --git a/config/initial-objects/report/140-report-certification-campaigns.xml b/config/initial-objects/report/140-report-certification-campaigns.xml index b6055a6438f..3668bda406e 100644 --- a/config/initial-objects/report/140-report-certification-campaigns.xml +++ b/config/initial-objects/report/140-report-certification-campaigns.xml @@ -12,7 +12,7 @@ oid="00000000-0000-0000-0000-000000000140"> Certification campaigns report All certification campaigns along with their state. - + @@ -53,14 +53,14 @@ - + name name - + owner ownerRef @@ -68,7 +68,7 @@ name - + startTimestamp startTimestamp @@ -76,7 +76,7 @@ owner - + endTimestamp endTimestamp @@ -84,7 +84,7 @@ startTimestamp - + cases case @@ -93,7 +93,7 @@ endTimestamp number - + state state @@ -101,7 +101,7 @@ cases - + stageNumber stageNumber @@ -109,7 +109,7 @@ state - + stageCases @@ -129,7 +129,7 @@ - + percentComplete @@ -156,7 +156,7 @@ AccessCertificationCampaignType true - + alsoClosedCampaigns boolean diff --git a/config/initial-objects/report/150-report-certification-cases.xml b/config/initial-objects/report/150-report-certification-cases.xml index 5767dabbc11..389af64d580 100644 --- a/config/initial-objects/report/150-report-certification-cases.xml +++ b/config/initial-objects/report/150-report-certification-cases.xml @@ -12,7 +12,7 @@ oid="00000000-0000-0000-0000-000000000150"> Certification cases report Cases within given certification campaign(s). - + @@ -35,7 +35,7 @@ - + object objectRef @@ -55,7 +55,7 @@ - + target targetRef @@ -76,7 +76,7 @@ - + campaignName @@ -95,7 +95,7 @@ - + reviewers @@ -113,7 +113,7 @@ - + lastReviewedOn @@ -132,7 +132,7 @@ - + reviewedBy @@ -151,7 +151,7 @@ - + iteration iteration @@ -159,7 +159,7 @@ reviewedBy - + inStageNumber stageNumber @@ -167,7 +167,7 @@ iteration - + outcome outcome @@ -186,7 +186,7 @@ - + comments @@ -205,7 +205,7 @@ - + remediedTimestamp remediedTimestamp @@ -218,7 +218,7 @@ AccessCertificationCaseType - + campaignRef c:ObjectReferenceType c:AccessCertificationCampaignType diff --git a/config/initial-objects/report/160-report-certification-work-items.xml b/config/initial-objects/report/160-report-certification-work-items.xml index 743c1d33aed..199b2e42052 100644 --- a/config/initial-objects/report/160-report-certification-work-items.xml +++ b/config/initial-objects/report/160-report-certification-work-items.xml @@ -13,7 +13,7 @@ oid="00000000-0000-0000-0000-000000000160"> Certification work items report Work items created for certification campaign(s). - + @@ -35,7 +35,7 @@ - + object objectRef @@ -55,7 +55,7 @@ - + target targetRef @@ -76,7 +76,7 @@ - + campaignName @@ -95,7 +95,7 @@ - + iteration @@ -113,7 +113,7 @@ - + stageNumber @@ -131,7 +131,7 @@ - + originalAssigneeRef @@ -149,7 +149,7 @@ - + deadline @@ -167,7 +167,7 @@ - + assigneeRef @@ -185,7 +185,7 @@ - + escalationLevel @@ -203,7 +203,7 @@ - + performerRef @@ -221,7 +221,7 @@ - + outcome @@ -241,7 +241,7 @@ - + comment @@ -259,7 +259,7 @@ - + outputChangeTimestamp @@ -277,7 +277,7 @@ - + closeTimestamp @@ -300,7 +300,7 @@ c:AccessCertificationCaseType - + campaignRef c:ObjectReferenceType c:AccessCertificationCampaignType @@ -313,7 +313,7 @@ - + stageNumber xsd:int @@ -325,7 +325,7 @@ - + iteration xsd:int @@ -337,7 +337,7 @@ - + workItems AccessCertificationWorkItemType diff --git a/config/initial-objects/report/170-report-simulation-objects.xml b/config/initial-objects/report/170-report-simulation-objects.xml index 946e5c434a2..da015b2fd19 100644 --- a/config/initial-objects/report/170-report-simulation-objects.xml +++ b/config/initial-objects/report/170-report-simulation-objects.xml @@ -12,7 +12,7 @@ oid="00000000-0000-0000-0000-286d76cea7c5"> Simulation report: Objects Objects processed by a given simulation. - + @@ -30,7 +30,7 @@ - + id - + oid oid @@ -61,42 +61,42 @@ id - + name name oid - + type type name - + archetype structuralArchetypeRef type - + resourceRef resourceObjectCoordinates/resourceRef archetype - + kind resourceObjectCoordinates/kind resourceRef - + intent resourceObjectCoordinates/intent kind - + tag resourceObjectCoordinates/tag intent - + objectMark - + state state objectMark - + resultStatus resultStatus state - + eventMarkRef eventMarkRef resultStatus - + message c:SimulationResultProcessedObjectType - + simulationResultRef c:ObjectReferenceType SimulationResultType @@ -164,7 +164,7 @@ - + objectMarks c:ObjectReferenceType diff --git a/config/initial-objects/report/171-report-simulation-objects-with-metrics.xml b/config/initial-objects/report/171-report-simulation-objects-with-metrics.xml index 8e4f6667696..f5ade32232a 100644 --- a/config/initial-objects/report/171-report-simulation-objects-with-metrics.xml +++ b/config/initial-objects/report/171-report-simulation-objects-with-metrics.xml @@ -13,7 +13,7 @@ oid="00000000-0000-0000-0000-616a5c5dbca8"> Simulation report: Objects with metrics Objects processed by a given simulation, along with values of individual metrics. - + @@ -31,7 +31,7 @@ - + id - + oid oid @@ -62,42 +62,42 @@ id - + name name oid - + type type name - + archetype structuralArchetypeRef type - + resourceRef resourceObjectCoordinates/resourceRef archetype - + kind resourceObjectCoordinates/kind resourceRef - + intent resourceObjectCoordinates/intent kind - + tag resourceObjectCoordinates/tag intent - + objectMark - + state state objectMark - + resultStatus resultStatus state - + eventMark - + explicitMetric - + selected - + value c:SimulationResultProcessedObjectType - + simulationResultRef c:ObjectReferenceType SimulationResultType @@ -234,7 +234,7 @@ - + showEventMarks xsd:boolean @@ -246,7 +246,7 @@ - + showExplicitMetrics xsd:boolean @@ -258,7 +258,7 @@ - + objectMarks c:ObjectReferenceType @@ -272,7 +272,7 @@ 5 - + metric diff --git a/config/initial-objects/report/172-report-simulation-items-changed.xml b/config/initial-objects/report/172-report-simulation-items-changed.xml index 293b8ce4d04..67e81d4c183 100644 --- a/config/initial-objects/report/172-report-simulation-items-changed.xml +++ b/config/initial-objects/report/172-report-simulation-items-changed.xml @@ -13,7 +13,7 @@ oid="00000000-0000-0000-0000-ea32deff43df"> Simulation report: Items changed Items changed within individual objects processed by a simulation. - + @@ -31,7 +31,7 @@ - + id - + oid oid @@ -62,42 +62,42 @@ id - + name name oid - + type type name - + archetype structuralArchetypeRef type - + resourceRef resourceObjectCoordinates/resourceRef archetype - + kind resourceObjectCoordinates/kind resourceRef - + intent resourceObjectCoordinates/intent kind - + tag resourceObjectCoordinates/tag intent - + objectMark - + state state objectMark - + resultStatus resultStatus state - + eventMarkRef eventMarkRef resultStatus - + itemChanged - + oldValues - + newValues - + valuesAdded - + valuesDeleted - + relatedAssignment - + relatedAssignmentId - + relatedAssignmentTarget - + relatedAssignmentTargetRelation - + relatedAssignmentResource - + relatedAssignmentKind - + relatedAssignmentIntent c:SimulationResultProcessedObjectType - + simulationResultRef c:ObjectReferenceType SimulationResultType @@ -395,7 +395,7 @@ - + pathsToInclude t:ItemPathType @@ -407,7 +407,7 @@ - + pathsToExclude t:ItemPathType @@ -419,7 +419,7 @@ - + includeOperationalItems xsd:boolean @@ -431,7 +431,7 @@ - + showIfNoDetails xsd:boolean @@ -443,7 +443,7 @@ - + objectMarks c:ObjectReferenceType @@ -457,7 +457,7 @@ 5 - + itemDelta @@ -478,7 +478,7 @@ splitParentRow - + detailsPresent xsd:boolean @@ -492,7 +492,7 @@ removeParentRow - + relatedAssignment AssignmentType diff --git a/config/initial-objects/report/173-report-simulation-values-changed.xml b/config/initial-objects/report/173-report-simulation-values-changed.xml index 166f65372de..880e2222539 100644 --- a/config/initial-objects/report/173-report-simulation-values-changed.xml +++ b/config/initial-objects/report/173-report-simulation-values-changed.xml @@ -13,7 +13,7 @@ oid="00000000-0000-0000-0000-61bc8211947c"> Simulation report: Values changed Item values changed within individual objects processed by a simulation. - + @@ -31,7 +31,7 @@ - + id - + oid oid @@ -62,42 +62,42 @@ id - + name name oid - + type type name - + archetype structuralArchetypeRef type - + resourceRef resourceObjectCoordinates/resourceRef archetype - + kind resourceObjectCoordinates/kind resourceRef - + intent resourceObjectCoordinates/intent kind - + tag resourceObjectCoordinates/tag intent - + objectMark - + state state objectMark - + resultStatus resultStatus state - + eventMarkRef eventMarkRef resultStatus - + itemChanged - + valueState - + value - + relatedAssignment - + relatedAssignmentId - + relatedAssignmentTarget - + relatedAssignmentTargetRelation - + relatedAssignmentResource - + relatedAssignmentKind - + relatedAssignmentIntent c:SimulationResultProcessedObjectType - + simulationResultRef c:ObjectReferenceType SimulationResultType @@ -349,7 +349,7 @@ - + pathsToInclude t:ItemPathType @@ -361,7 +361,7 @@ - + pathsToExclude t:ItemPathType @@ -373,7 +373,7 @@ - + includeOperationalItems xsd:boolean @@ -385,7 +385,7 @@ - + showIfNoDetails xsd:boolean @@ -397,7 +397,7 @@ - + objectMarks c:ObjectReferenceType @@ -411,7 +411,7 @@ 5 - + itemDelta @@ -433,7 +433,7 @@ splitParentRow - + valueWithState @@ -450,7 +450,7 @@ splitParentRow - + detailsPresent xsd:boolean @@ -464,7 +464,7 @@ removeParentRow - + relatedAssignment AssignmentType diff --git a/config/initial-objects/report/180-report-simulation-results.xml b/config/initial-objects/report/180-report-simulation-results.xml index c0ed88018f9..e0fb671e6ed 100644 --- a/config/initial-objects/report/180-report-simulation-results.xml +++ b/config/initial-objects/report/180-report-simulation-results.xml @@ -11,7 +11,7 @@ oid="00000000-0000-0000-0000-97631b84fde7"> Simulation report: Results Individual simulation results, along with respective metric values. - + @@ -19,7 +19,7 @@ - + oid OID of the simulation result object. @@ -40,7 +40,7 @@ - + name Name of the simulation result object. @@ -51,7 +51,7 @@ name oid - + definitionIdentifier Identifier of the simulation result definition used (if any). @@ -67,17 +67,17 @@ name - + startTimestamp startTimestamp definitionIdentifier - + endTimestamp endTimestamp startTimestamp - + rootTaskRef Task under which this simulation executes or executed. (Empty for foreground simulations.) @@ -93,7 +93,7 @@ endTimestamp - + configuration configurationUsed/predefined @@ -107,7 +107,7 @@ rootTaskRef - + builtInMetric Built-in metric identifier corresponding to the metric row. (If applicable.) @@ -133,7 +133,7 @@ - + eventMark Event mark corresponding to the metric row. (If applicable.) @@ -159,7 +159,7 @@ - + explicitMetric Explicit metric identifier corresponding to the metric row. (If applicable.) @@ -185,7 +185,7 @@ - + aggregationFunction - + scopeType Type of objects (user, role, org, shadow, ...). @@ -235,7 +235,7 @@ - + scopeArchetype Structural archetype of the objects. Applicable only to focal objects. @@ -265,7 +265,7 @@ - + scopeResource Resource on which the projection (shadow) resides. Applicable only to projections. @@ -295,7 +295,7 @@ - + scopeKind Kind of the projection (shadow). Applicable only to projections. @@ -321,7 +321,7 @@ - + scopeIntent Intent of the projection (shadow). Applicable only to projections. @@ -347,7 +347,7 @@ - + value Aggregated value of the metric for given partition. @@ -373,7 +373,7 @@ - + selectionSize Number of objects selected by given metric. @@ -401,7 +401,7 @@ - + selectionTotalValue Sum of metric values for all objects selected by the metric. @@ -427,7 +427,7 @@ - + domainSize Number of objects on which given metric was evaluated. @@ -453,7 +453,7 @@ - + domainTotalValue Sum of metric values for all objects. @@ -481,7 +481,7 @@ c:SimulationResultType - + metric SimulationMetricValuesType @@ -494,7 +494,7 @@ splitParentRow - + partition SimulationMetricPartitionType diff --git a/config/initial-objects/report/200-report-indirect-assignments.xml b/config/initial-objects/report/200-report-indirect-assignments.xml index d0a7f07fcdd..6fee49e50b1 100644 --- a/config/initial-objects/report/200-report-indirect-assignments.xml +++ b/config/initial-objects/report/200-report-indirect-assignments.xml @@ -11,7 +11,7 @@ oid="00000000-0000-0000-0000-b8249b79d2b5"> Indirect assignment report Shows information stored in roleMembershipRef value metadata. - + @@ -42,17 +42,17 @@ - + userName string - + roleRef c:ObjectReferenceType c:AbstractRoleType - + - + user @@ -92,7 +92,7 @@ - + nameColumn @@ -107,7 +107,7 @@ - + archetypeName @@ -122,7 +122,7 @@ - + relation @@ -137,7 +137,7 @@ - + allPath @@ -154,7 +154,7 @@ - + parent @@ -181,7 +181,7 @@ - + activation @@ -197,7 +197,7 @@ - + validTo @@ -212,7 +212,7 @@ - + since @@ -227,7 +227,7 @@ - + createChannel diff --git a/config/initial-objects/role/030-role-superuser.xml b/config/initial-objects/role/030-role-superuser.xml index a45a8203a5d..45b7a67841b 100644 --- a/config/initial-objects/role/030-role-superuser.xml +++ b/config/initial-objects/role/030-role-superuser.xml @@ -10,10 +10,10 @@ Superuser Role that gives user full authorization in MidPoint. true - + - + http://midpoint.evolveum.com/xml/ns/public/security/authorization-3#all diff --git a/config/initial-objects/role/040-role-enduser.xml b/config/initial-objects/role/040-role-enduser.xml index 0cc9d17369b..aa48de9d542 100644 --- a/config/initial-objects/role/040-role-enduser.xml +++ b/config/initial-objects/role/040-role-enduser.xml @@ -20,52 +20,52 @@ Therefore we have chosen not to mark it with any archetype to avoid risk of creating a confusing situation. --> - + gui-self-service-access Allow access to all self-service operations in GUI. http://midpoint.evolveum.com/xml/ns/public/security/authorization-ui-3#selfAll - + self-read Allow to read all the properties of "self" object. I.e. every logged-in user can read object that represent his own identity. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + self - + self-shadow-read Allow to read all the properties of all the shadows that belong to "self" object. I.e. every logged-in user can read all his accounts. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + ShadowType self - + self-persona-read Allow to read all the personas of currently logged-in user. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + UserType self - + self-credentials-request Allow to modify user's own credentials. @@ -73,12 +73,12 @@ http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#changeCredentials request - + self credentials - + self-shadow-credentials-request Allow to modify credentials of all users accounts. @@ -86,7 +86,7 @@ http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#changeCredentials request - + ShadowType self @@ -94,13 +94,13 @@ credentials - + read-requestable-roles Allow to read requestable roles. This allows to search for requestable roles in user interface. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + RoleType @@ -111,7 +111,7 @@ - + requestable-role-details Allow to show details of requestable roles in the user interface. @@ -120,7 +120,7 @@ - + assign-requestable-roles Allow to assign requestable roles. This allows to request roles in a request-and-approve process. @@ -130,10 +130,10 @@ http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#assign request - + self - + RoleType @@ -144,7 +144,7 @@ org:default - + self-execution-modify Authorization that allows to self-modification of some properties, but only in execution phase. @@ -154,13 +154,13 @@ http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#modify execution - + self credentials assignment - + self-shadow-execution-add-modify-delete Authorization that allows to self-modification of user's accounts, but only in execution phase. @@ -170,14 +170,14 @@ http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#modify http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#delete execution - + ShadowType self - + assignment-target-get Authorization that allows to read all the object that are possible assignment targets. We want that @@ -186,56 +186,56 @@ selected properties such as name and description. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#get - + OrgType - + ResourceType - + RoleType - + ServiceType - + UserType - + operational-objects-get Authorization that allows to read all the object that are possible to use for (not only) GUI customizations. E.g there might be lookup tables used for attributes, custom form types defined, etc. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#get - + LookupTableType - + assignment-target-read-case Authorization that allows to read approval status of cases. This is used to display requests to the end users, especially in the "My Requests" box in user dashboard. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + CaseType self - + self-owned-task-read Authorization that allows to see all tasks owned by a currently logged-in user. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + TaskType self @@ -243,27 +243,27 @@ - + UserType - + myWorkItems hidden - + myHistory hidden - + listUsersWidget hidden - + listResourcesWidget hidden - + myRequests - + viewAll hidden @@ -271,7 +271,7 @@ UserType - + history hidden diff --git a/config/initial-objects/role/041-role-approver.xml b/config/initial-objects/role/041-role-approver.xml index dcd23dbd822..93c2f730d0a 100644 --- a/config/initial-objects/role/041-role-approver.xml +++ b/config/initial-objects/role/041-role-approver.xml @@ -10,10 +10,10 @@ xmlns:q="http://prism.evolveum.com/xml/ns/public/query-3"> Approver Role authorizing users to make approval decisions on work items. - + - + gui-approver-access Allow access to list of work items in GUI. Allow access to pages that show object details, @@ -27,7 +27,7 @@ http://midpoint.evolveum.com/xml/ns/public/security/authorization-ui-3#orgUnit http://midpoint.evolveum.com/xml/ns/public/security/authorization-ui-3#service - + workitems-delegate Allow delegation of own work items. @@ -45,7 +45,7 @@ WorkItemType --> - + cases-read Allow to see the requester of the operation that is being approved and the current delta. @@ -53,20 +53,20 @@ to other items as well. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + CaseType requesterRef approvalContext - + users-read Allow to read basic user properties to be able to display requestor details in the approval forms. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + UserType name @@ -76,13 +76,13 @@ employeeType employeeNumber - + roles-read Allow to read basic role properties to be able to display details of the requested role. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + RoleType name @@ -92,13 +92,13 @@ riskLevel roleType - + orgs-read Allow to read basic org properties to be able to display details of the requested org. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + OrgType name @@ -108,13 +108,13 @@ riskLevel orgType - + services-read Allow to read basic service properties to be able to display details of the requested service. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + ServiceType name diff --git a/config/initial-objects/role/042-role-reviewer.xml b/config/initial-objects/role/042-role-reviewer.xml index f552738e6af..51118943b4d 100644 --- a/config/initial-objects/role/042-role-reviewer.xml +++ b/config/initial-objects/role/042-role-reviewer.xml @@ -10,10 +10,10 @@ xmlns:q="http://prism.evolveum.com/xml/ns/public/query-3"> Reviewer Role authorizing users to make decisions on certification cases. - + - + gui-reviewer-access Allow access to list of certification cases in GUI. Allow access to pages that show object details, @@ -25,18 +25,18 @@ http://midpoint.evolveum.com/xml/ns/public/security/authorization-ui-3#orgUnit http://midpoint.evolveum.com/xml/ns/public/security/authorization-ui-3#service - + read-and-make-decisions http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#readOwnCertificationDecisions http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#recordCertificationDecision - + users-read Allow to read basic user properties. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + UserType name @@ -46,13 +46,13 @@ employeeType employeeNumber - + roles-read Allow to read basic role properties. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + RoleType name @@ -62,13 +62,13 @@ riskLevel roleType - + orgs-read Allow to read basic org properties. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + OrgType name @@ -78,13 +78,13 @@ riskLevel orgType - + services-read Allow to read basic service properties. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + ServiceType name diff --git a/config/initial-objects/role/043-role-delegator.xml b/config/initial-objects/role/043-role-delegator.xml index fe45d69836a..19177f6cba4 100644 --- a/config/initial-objects/role/043-role-delegator.xml +++ b/config/initial-objects/role/043-role-delegator.xml @@ -10,28 +10,28 @@ xmlns:q="http://prism.evolveum.com/xml/ns/public/query-3"> Delegator Role authorizing users to delegate their own privileges to any other user. - + - + gui-delegator-access Allow access to the delegate functionality (e.g. "add delegation" button). http://midpoint.evolveum.com/xml/ns/public/security/authorization-ui-3#delegate - + delegator-req http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#delegate request - + UserType - + self - + delegator-exec-user Quite strong universal execution rights are needed here. We are going to modify other users @@ -39,11 +39,11 @@ http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#modify execution - + UserType - + delegator-exec-shadow Quite strong universal execution rights are needed here. We are going to modify other users @@ -54,11 +54,11 @@ http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#modify http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#delete execution - + ShadowType - + delegator-read-delagate-assignments Authorization to read the assignments and assignment-related items from my delegates. @@ -67,7 +67,7 @@ object. Therefore authorization to read just "self" will not display the delegations. http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#read - + UserType self @@ -78,9 +78,9 @@ delegatedRef - + UserType - + myWorkItems hidden diff --git a/config/initial-objects/security-policy/015-security-policy.xml b/config/initial-objects/security-policy/015-security-policy.xml index 1ff49dfe814..f80a32ad37f 100644 --- a/config/initial-objects/security-policy/015-security-policy.xml +++ b/config/initial-objects/security-policy/015-security-policy.xml @@ -11,14 +11,14 @@ Default Security Policy - + loginForm - + httpBasic - + admin-gui-default Default gui sequence @@ -26,33 +26,33 @@ http://midpoint.evolveum.com/xml/ns/public/common/channels-3#user gui-default - + loginForm 1 sufficient - + rest-default true http://midpoint.evolveum.com/xml/ns/public/common/channels-3#rest rest-default - + httpBasic 1 sufficient - + actuator-default true http://midpoint.evolveum.com/xml/ns/public/common/channels-3#actuator actuator-default - + httpBasic 1 sufficient diff --git a/config/initial-objects/service/610-service-identity-recovery.xml b/config/initial-objects/service/610-service-identity-recovery.xml index 2d06a9fb77c..2f6b7bc5f67 100644 --- a/config/initial-objects/service/610-service-identity-recovery.xml +++ b/config/initial-objects/service/610-service-identity-recovery.xml @@ -9,7 +9,7 @@ xmlns="http://midpoint.evolveum.com/xml/ns/public/common/common-3"> Identity recovery Service intended for identity recovery flow. The necessary for this flow authorizations are granted within this service. - + gui-identity-recovery-access Allow access to identity recovery results page. diff --git a/config/initial-objects/system-configuration/000-system-configuration.xml b/config/initial-objects/system-configuration/000-system-configuration.xml index 114b68290c3..4bc3fa2bdf3 100644 --- a/config/initial-objects/system-configuration/000-system-configuration.xml +++ b/config/initial-objects/system-configuration/000-system-configuration.xml @@ -18,12 +18,12 @@ - + OFF org.springframework.security.web.DefaultSecurityFilterChain - + OFF @@ -33,48 +33,49 @@ Otherwise the log is filled-in with (innocent but ugly-looking) messages like "ERROR (o.h.engine.jdbc.batch.internal.BatchingBatch): HHH000315: Exception executing batch [Deadlock detected. The current transaction was rolled back." --> - + OFF org.hibernate.engine.jdbc.batch.internal.BatchingBatch - + WARN org.hibernate.engine.jdbc.batch.internal.AbstractBatchImpl - + OFF org.hibernate.internal.ExceptionMapperStandardImpl - + WARN org.apache.wicket.resource.PropertiesFactory - + ERROR org.springframework.context.support.ResourceBundleMessageSource - + INFO com.evolveum.midpoint.model.impl.lens.projector.Projector - + INFO com.evolveum.midpoint.model.impl.lens.Clockwork - %date [%X{subsystem}] [%thread] %level \(%logger\): %msg%n + MIDPOINT_LOG ${midpoint.home}/log/midpoint.log ${midpoint.home}/log/midpoint-%d{yyyy-MM-dd}.%i.log 10 @@ -82,9 +83,10 @@ true - %date %level: %msg%n + MIDPOINT_PROFILE_LOG ${midpoint.home}/log/midpoint-profile.log ${midpoint.home}/log/midpoint-profile-%d{yyyy-MM-dd}.%i.log 10 @@ -108,7 +110,7 @@ - + performance Performance tracing true @@ -117,7 +119,7 @@ true true - + functional Functional tracing true @@ -125,11 +127,11 @@ true true true - + normal - + functional-model-logging Functional tracing (with model logging) true @@ -138,16 +140,16 @@ true true - + com.evolveum.midpoint.model TRACE - + normal - + functional-sql-logging Functional tracing (with SQL logging) true @@ -156,21 +158,24 @@ true true - + org.hibernate.SQL TRACE - + normal - + UserType - + + search + + myAccesses 10 - + viewAll - + requestAccess - + myRequests 20 - + viewAll - + myWorkItems 40 - + viewAll - + myAccounts 30 - + viewAll - + profileWidget linkWidget - + profile-widget-action /self/profile/user - + credentialsWidget linkWidget - + credentials-widget-action /self/credentials - + listResourcesWidget linkWidget - + list-resources-widget-action /admin/resources - + listUsersWidget linkWidget - + list-resources-widget-action /admin/users @@ -422,7 +427,7 @@ - + my-cases @@ -445,7 +450,7 @@ - + manual-case-view @@ -466,7 +471,7 @@ - + operation-request-case-view @@ -487,7 +492,7 @@ - + approval-case-view @@ -508,7 +513,7 @@ - + correlation-case-view @@ -528,7 +533,7 @@ - + reconciliation-tasks-view 30 TaskType @@ -536,7 +541,7 @@ - + recomputation-tasks-view 30 TaskType @@ -544,7 +549,7 @@ - + import-tasks-view 30 TaskType @@ -552,7 +557,7 @@ - + live-sync-tasks-view 30 TaskType @@ -560,7 +565,7 @@ - + async-update-tasks-view 30 TaskType @@ -568,7 +573,7 @@ - + cleanup-tasks-view 30 TaskType @@ -576,7 +581,7 @@ - + report-tasks-view @@ -598,7 +603,7 @@ - + non-iterative-bulk-tasks-view 30 TaskType @@ -606,7 +611,7 @@ - + iterative-bulk-tasks-view 30 TaskType @@ -614,7 +619,7 @@ - + report-import-task-view 30 add @@ -623,7 +628,7 @@ - + export-report-tasks-view add 30 @@ -634,7 +639,7 @@ - + export-report-distributed-tasks-view add 30 @@ -645,7 +650,7 @@ - + shadow-integrity-check-task-view 30 add @@ -654,7 +659,7 @@ - + shadows-refresh-task-view 30 add @@ -663,7 +668,7 @@ - + objects-delete-task-view 30 add @@ -672,7 +677,7 @@ - + shadows-delete-long-time-not-updated-task-view 30 add @@ -681,7 +686,7 @@ - + execute-change-task-view 30 add @@ -690,7 +695,7 @@ - + execute-deltas-task-view 30 add @@ -699,7 +704,7 @@ - + reindex-repository-task-view 30 add @@ -708,7 +713,7 @@ - + object-integrity-check-task-view 30 add @@ -717,7 +722,7 @@ - + validity-task-view 30 add @@ -726,7 +731,7 @@ - + trigger-task-view 30 add @@ -735,7 +740,7 @@ - + propagation-task-view 30 add @@ -744,7 +749,7 @@ - + multi-propagation-task-view 30 add @@ -753,7 +758,7 @@ - + certification-tasks-view 30 TaskType @@ -761,7 +766,7 @@ - + approval-tasks-view 30 TaskType @@ -769,7 +774,7 @@ - + utility-tasks-view 30 TaskType @@ -777,7 +782,7 @@ - + system-tasks-view 30 TaskType @@ -785,21 +790,21 @@ - + dashboard-reports-view ReportType - + collection-reports-view ReportType - + application-role add RoleType @@ -807,7 +812,7 @@ - + business-role add RoleType @@ -815,7 +820,7 @@ - + application @@ -825,7 +830,7 @@ - + event-mark c:MarkType @@ -834,7 +839,7 @@ - + object-mark c:MarkType @@ -843,134 +848,194 @@ + + Persons + This view displays all users with archetype "Person" + person-view + 10 + UserType + + + + + + + + + Allow searching for users having account on specific resource. Intent is not considered. The search item is not displayed by default + (visibleByDefault=false). + + true + + + linkRef/@ matches ( + . type ShadowType + and resourceRef/@/name = `resourceParameter?.getName()?.getOrig()` + and kind = "account" ) + + + + + + + resourceParameter + c:ObjectReferenceType + ResourceType + + + + Allow searching for users not having account on specific resource. Intent is not considered. The search item is not displayed by default + (visibleByDefault=false). + + true + + + linkRef/@ not matches ( + . type ShadowType + and resourceRef/@/name = `resourceParameter?.getName()?.getOrig()` + and kind = "account" ) + + + + + + + resourceParameter + c:ObjectReferenceType + ResourceType + + + + + - + c:TaskType - + advanced-options-panel formPanel - + advanced-options 150 - + cleanupAfterCompletion - + threadStopAction - + binding - + dependent - + operational-attributes-panel formPanel - + operational-attributes 900 - + executionState - + schedulingState - + node - + nodeAsObserved - + resultStatus - + result - + nextRunStartTimestamp - + nextRetryTimestamp - + unpauseAction - + taskIdentifier - + parent - + waitingReason - + stateBeforeSuspend - + schedulingStateBeforeSuspend - + otherHandlersUriStack - + channel - + subtaskRef - + dependentTaskRef - + lastRunStartTimestamp - + lastRunFinishTimestamp - + completionTimestamp - + 910 hidden operation-attributes-progress - + progress - + expectedTotal - + stalledSince - + c:UserType - + applications @@ -992,313 +1057,313 @@ - - + + rw-type-basic - + basic - + schemaHandling/objectType/displayName visible - + schemaHandling/objectType/description visible - + schemaHandling/objectType/kind visible - + schemaHandling/objectType/intent visible - + schemaHandling/objectType/securityPolicyRef visible - + schemaHandling/objectType/default visible - + hidden schemaHandling/objectType rw-type-basic - + rw-type-delineation - + delineation - + schemaHandling/objectType/delineation/objectClass visible - + schemaHandling/objectType/delineation/auxiliaryObjectClass visible - + schemaHandling/objectType/delineation/searchHierarchyScope visible - + schemaHandling/objectType/delineation/filter visible - + schemaHandling/objectType/delineation/classificationCondition visible - + hidden schemaHandling/objectType/delineation rw-type-delineation - + rw-attribute-limitations - + limitationsMapping - + schemaHandling/objectType/attribute/limitations/access/read visible - + schemaHandling/objectType/attribute/limitations/access/add visible - + schemaHandling/objectType/attribute/limitations/access/modify visible - + schemaHandling/objectType/attribute/limitations/minOccurs visible - + schemaHandling/objectType/attribute/limitations/maxOccurs visible - + schemaHandling/objectType/attribute/limitations/processing visible - + hidden schemaHandling/objectType/attribute/limitations rw-attribute-limitations - + rw-synchronization-reaction-main - + reactionMainSetting - + schemaHandling/objectType/synchronization/reaction/name visible - + schemaHandling/objectType/synchronization/reaction/description visible - + schemaHandling/objectType/synchronization/reaction/situation visible - + hidden schemaHandling/objectType/synchronization/reaction rw-synchronization-reaction-main - + rw-synchronization-reaction-optional - + reactionOptionalSetting - + schemaHandling/objectType/synchronization/reaction/condition visible - + schemaHandling/objectType/synchronization/reaction/channel visible - + schemaHandling/objectType/synchronization/reaction/order visible - + hidden schemaHandling/objectType/synchronization/reaction rw-synchronization-reaction-optional - + rw-attribute - + mainConfigurationAttribute - + schemaHandling/objectType/attribute/ref visible - + schemaHandling/objectType/attribute/displayName visible - + schemaHandling/objectType/attribute/help visible - + schemaHandling/objectType/attribute/description visible - + schemaHandling/objectType/attribute/tolerant visible - + schemaHandling/objectType/attribute/exclusiveStrong visible - + schemaHandling/objectType/attribute/readReplaceMode visible - + schemaHandling/objectType/attribute/fetchStrategy visible - + schemaHandling/objectType/attribute/matchingRule visible - + hidden schemaHandling/objectType/attribute rw-attribute - + rw-association - + association - + schemaHandling/objectType/association/ref visible - + schemaHandling/objectType/association/displayName visible - + schemaHandling/objectType/association/description visible - + schemaHandling/objectType/association/auxiliaryObjectClass visible - + schemaHandling/objectType/association/kind visible - + schemaHandling/objectType/association/intent visible - + schemaHandling/objectType/association/direction visible - + schemaHandling/objectType/association/associationAttribute visible - + schemaHandling/objectType/association/shortcutAssociationAttribute visible - + schemaHandling/objectType/association/valueAttribute visible - + schemaHandling/objectType/association/shortcutValueAttribute visible - + schemaHandling/objectType/association/explicitReferentialIntegrity visible - + hidden schemaHandling/objectType/association rw-association - - + + rw-connectorConfiguration-partial - + required - + connectorConfiguration/configurationProperties/jdbcUrlTemplate - + connectorConfiguration/configurationProperties/jdbcDriver - + connectorConfiguration/configurationProperties/password - + connectorConfiguration/configurationProperties/user - + connectorConfiguration/configurationProperties/port - + connectorConfiguration/configurationProperties/host - + connectorConfiguration/configurationProperties/database - + hidden connectorConfiguration/configurationProperties @@ -1320,33 +1385,33 @@ - - + + rw-connectorConfiguration-partial - + required - + connectorConfiguration/configurationProperties/host - + connectorConfiguration/configurationProperties/port - + connectorConfiguration/configurationProperties/connectionSecurity - + connectorConfiguration/configurationProperties/bindDn visible - + connectorConfiguration/configurationProperties/bindPassword visible - + hidden connectorConfiguration/configurationProperties @@ -1368,33 +1433,33 @@ - - + + rw-connectorConfiguration-partial - + required - + connectorConfiguration/configurationProperties/host - + connectorConfiguration/configurationProperties/port - + connectorConfiguration/configurationProperties/connectionSecurity - + connectorConfiguration/configurationProperties/bindDn visible - + connectorConfiguration/configurationProperties/bindPassword visible - + hidden connectorConfiguration/configurationProperties @@ -1417,22 +1482,22 @@ - + admin-dashboard - + allRoles true allRoles - + allOrgs allOrgs - + allServices allServices @@ -1441,7 +1506,7 @@ - + safe "Safe" expression profile. It is supposed to contain only operations that are "safe", @@ -1452,26 +1517,26 @@ without any guarantees. Use at your own risk. deny - + asIs allow - + path allow - + value allow - + const allow - + script deny - - + script-safe deny - + com.evolveum.midpoint.xml.ns._public.common.common_3 MidPoint common schema - generated bean classes allow - + com.evolveum.prism.xml.ns._public.types_3 Prism schema - bean classes allow - + java.lang.Integer allow - + java.lang.Object Basic Java operations. deny - + equals allow - + hashCode allow - + java.lang.String String operations are generally safe. But Groovy is adding execute() method which is very dangerous. allow - + execute deny - + java.lang.CharSequence allow - + java.lang.Enum allow - + java.util.List List operations are generally safe. But Groovy is adding execute() method which is very dangerous. allow - + execute deny - + java.util.ArrayList List operations are generally safe. But Groovy is adding execute() method which is very dangerous. allow - + execute deny - + java.util.Map allow - + java.util.HashMap allow - + java.util.Date allow - + javax.xml.namespace.QName allow - + javax.xml.datatype.XMLGregorianCalendar allow - + java.lang.System Just a few methods of System are safe enough. deny - + currentTimeMillis allow - + java.lang.IllegalStateException Basic Java exception. Also used in test. allow - + java.lang.IllegalArgumentException Basic Java exception. allow - + com.evolveum.midpoint.model.common.expression.functions.BasicExpressionFunctions MidPoint basic functions library allow - + com.evolveum.midpoint.model.common.expression.functions.LogExpressionFunctions MidPoint logging functions library allow - + com.evolveum.midpoint.report.impl.ReportFunctions MidPoint report functions library allow - + org.apache.commons.lang3.StringUtils Apache Commons: Strings allow diff --git a/config/initial-objects/task/550-task-cleanup.xml b/config/initial-objects/task/550-task-cleanup.xml index bcb7fc03ed0..a158cb7d014 100644 --- a/config/initial-objects/task/550-task-cleanup.xml +++ b/config/initial-objects/task/550-task-cleanup.xml @@ -10,7 +10,7 @@ Cleanup A system task that repeatedly checks for outdated objects (e.g. closed tasks, old audit records) and removes them. - + diff --git a/config/initial-objects/task/560-task-validity.xml b/config/initial-objects/task/560-task-validity.xml index f5a6e685382..1c7d7c49c40 100644 --- a/config/initial-objects/task/560-task-validity.xml +++ b/config/initial-objects/task/560-task-validity.xml @@ -10,10 +10,10 @@ Validity Scanner A system task that maintains effective status of objects, based on their validity time constraints. - + - + diff --git a/config/initial-objects/task/570-task-trigger.xml b/config/initial-objects/task/570-task-trigger.xml index 46066aabe1c..07b2a0c111a 100644 --- a/config/initial-objects/task/570-task-trigger.xml +++ b/config/initial-objects/task/570-task-trigger.xml @@ -10,10 +10,10 @@ Trigger Scanner A system task that executes triggers attached to objects. - + - + diff --git a/config/initial-objects/user/050-user-administrator.xml b/config/initial-objects/user/050-user-administrator.xml index a8ac8615305..6ea887607a6 100644 --- a/config/initial-objects/user/050-user-administrator.xml +++ b/config/initial-objects/user/050-user-administrator.xml @@ -14,10 +14,10 @@ midPoint Administrator midPoint Administrator - + - +