New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Group assignment for users should be done at /Group not through /Users endpoint #42

jgomer2001 opened this Issue Oct 23, 2017 · 1 comment


None yet
1 participant

jgomer2001 commented Oct 23, 2017

Citing section 4.1.2 of RFC 7643 (description of user's groups attribute):

Since this attribute has a mutability of "readOnly", group membership changes MUST be applied via the "Group" Resource (Section 4.2)

Current implementation of Users endpoint allows the modification of the groups attribute in creation (POST), and modification (PUT) operations.

Correct behavior will be ignoring the groups passed as in this case data is read-only.

@jgomer2001 jgomer2001 added the bug label Oct 23, 2017

@jgomer2001 jgomer2001 added this to the CE 3.2 milestone Oct 23, 2017

@jgomer2001 jgomer2001 self-assigned this Oct 23, 2017


This comment has been minimized.


jgomer2001 commented Jan 3, 2018

Relevant test case here.

@jgomer2001 jgomer2001 closed this Jan 3, 2018

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment