Child pages
  • Get Attribute Assignments
Skip to end of metadata
Go to start of metadata

Grouper Web Services

Description

Get attribute assignments.  These attributes can be on groups, stems, members, memberships (immediate or any), or attribute definitions.  If you want to retrieve attribute assignments assigned to other attributes, then pass a flag to the assignment lookup to include assignments on the returned assignments.

You can lookup attributes by attribute definition, attribute definition name, attribute assign id, or the owner lookup (e.g. group name or stem uuid).

All returned attribute assignments will be filtered for security based on the logged in or acted as user (security rules are on attribute framework wiki)

The returned data will include the attribute assignments, value(s) on those assignments, and a normalized list of references (owner objects e.g. group/stem/etc, attribute definitions, attribute names, etc)

You can lookup assignments by multiple owners, definitions, etc

AttributeAssignType is a required field, but cannot be an assignment on assignment, must be: group, member, stem, any_mem, imm_mem, attr_def

In 2.1.1+ you can search by more params:

You can search by value (you need to pass the value type and value), You can also search for assignments on assignments,
and include the assignments from assignments (e.g. to know which group it is assigned to). You can filter by attributeDefType.
In all, these are the new params for lite or non-lite operations including grouper client:

attributeDefValueType: required if sending theValue, can be: floating, integer, memberId, string, timestamp
theValue: value if you are passing in one attributeDefNameLookup
includeAssignmentsFromAssignments: T|F if you are finding an assignment that is an assignmentOnAssignment, then get the assignment which tells you the owner as well
attributeDefType: null for all, or specify an AttributeDefType e.g. attr, limit, service, type, limit, perm
wsAssignAssignOwnerAttributeAssignLookups: if looking for assignments on assignments, this is the assignment the assignment is assigned to
wsAssignAssignOwnerAttributeDefLookups: if looking for assignments on assignments, this is the attribute definition of the assignment the assignment is assigned to
wsAssignAssignOwnerAttributeDefNameLookups: if looking for assignments on assignments, this is the attribute def name of the assignment the assignment is assigned to
wsAssignAssignOwnerActions: if looking for assignments on assignments, this are the actions of the assignment the assignment is assigned to

Features

  • Can base attribute assign list based on action, active, etc
  • Lookup owner or other objects by object lookup (by id, name, etc)
  • Returns group / subject information, can be detailed or not
  • Can actAs another user

Get attribute assignments lite service

  • Accepts one group, or one subject, or stem, etc to get attribute assignments for
  • Documentation: SOAP (click on getAttributeAssignmentsLite), REST (click on getAttributeAssignmentsLite)
  • For REST, the request can put data in query string (in URL or request body)
  • REST request (colon is escaped to %3A):
    • GET /grouper-ws/servicesRest/v1_6_000/attributeAssignments
    • Note: if passing data in request body e.g. actAs, use a POST
  • (see documentation above for details): Request object, response object
  • Response codes
  • Samples (all files with "Lite" in them, click on "download" to see file)

Get attribute assignments service

  • Accepts multiple groups or subjects or membershipIds (or combination) etc to retrieve lists of attribute assignments
  • Documentation: SOAP (click on getAttributeAssignments), REST (click on getAttributeAssignments)
  • REST request (colon is escaped to %3A):
    • POST /grouper-ws/servicesRest/v1_6_000/attributeAssignments
  • (see documentation above for details): Request object, response object
  • Response codes overall
  • Returns an overall status
  • Samples (all files without "Lite" in them, click on "download" to see files)


Example getting groups with attribute and value assigned

[mchyzer@flash pennGroupsClient-2.5.0]$ java -jar grouperClient-2.5.36.jar --operation=getAttributeAssignmentsWs --attributeAssignType=group --attributeDefNameNames=penn:etc:pspng:provision_to --attributeDefValueType=string --value=pspng_oneprod --debug=true
Reading resource: grouper.client.properties, from: /home/mchyzer/grouper/pennGroupsClient-2.5.0/grouper.client.properties
WebService: connecting as user: 'mchyzer'
WebService: connecting to URL: 'https://grouperWs.server.whatever/grouperWs/servicesRest/2.5.36/attributeAssignments'

################ REQUEST START (indented) ###############

POST /grouperWs/servicesRest/2.5.36/attributeAssignments HTTP/1.1
Connection: close
Authorization: Basic xxxxxxxxxxxxxxxx
User-Agent: Jakarta Commons-HttpClient/3.1
Host: grouperWs.server.whatever:-1
Content-Length: 360
Content-Type: text/xml; charset=UTF-8

<WsRestGetAttributeAssignmentsRequest>
  <attributeDefValueType>string</attributeDefValueType>
  <theValue>pspng_oneprod</theValue>
  <attributeAssignType>group</attributeAssignType>
  <wsAttributeDefNameLookups>
    <WsAttributeDefNameLookup>
      <name>penn:etc:pspng:provision_to</name>
    </WsAttributeDefNameLookup>
  </wsAttributeDefNameLookups>
</WsRestGetAttributeAssignmentsRequest>

################ REQUEST END ###############



################ RESPONSE START (indented) ###############

HTTP/1.1 200 OK
Date: Tue, 30 Mar 2021 15:54:49 GMT
Content-Type: application/xml;charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips
Strict-Transport-Security: max-age=15768000
X-Grouper-resultCode: SUCCESS
X-Grouper-success: T
X-Grouper-resultCode2: NONE

<WsGetAttributeAssignmentsResults>
  <wsAttributeDefs>
    <WsAttributeDef>
      <idIndex>10058</idIndex>
      <extension>provision_to_def</extension>
      <name>penn:etc:pspng:provision_to_def</name>
      <uuid>48c65c683b224378afed66a90d49dbc6</uuid>
      <attributeDefType>type</attributeDefType>
      <multiAssignable>T</multiAssignable>
      <multiValued>F</multiValued>
      <valueType>string</valueType>
      <assignToAttributeDef>F</assignToAttributeDef>
      <assignToAttributeDefAssignment>F</assignToAttributeDefAssignment>
      <assignToEffectiveMembership>F</assignToEffectiveMembership>
      <assignToEffectiveMembershipAssignment>F</assignToEffectiveMembershipAssignment>
      <assignToGroup>F</assignToGroup>
      <assignToGroupAssignment>F</assignToGroupAssignment>
      <assignToImmediateMembership>F</assignToImmediateMembership>
      <assignToImmediateMembershipAssignment>F</assignToImmediateMembershipAssignment>
      <assignToMember>F</assignToMember>
      <assignToMemberAssignment>F</assignToMemberAssignment>
      <assignToStem>F</assignToStem>
      <assignToStemAssignment>F</assignToStemAssignment>
    </WsAttributeDef>
  </wsAttributeDefs>
  <wsAttributeDefNames>
    <WsAttributeDefName>
      <idIndex>12987</idIndex>
      <extension>provision_to</extension>
      <displayExtension>provision_to</displayExtension>
      <description>Defines what provisioners should process a group or groups within a folder</description>
      <displayName>penn:etc:pspng:provision_to</displayName>
      <name>penn:etc:pspng:provision_to</name>
      <uuid>9f861e04cc794ea0bf79c29c0b116f7b</uuid>
      <attributeDefId>48c65c683b224378afed66a90d49dbc6</attributeDefId>
      <attributeDefName>penn:etc:pspng:provision_to_def</attributeDefName>
    </WsAttributeDefName>
  </wsAttributeDefNames>
  <wsAttributeAssigns>
    <WsAttributeAssign>
      <disallowed>F</disallowed>
      <attributeAssignActionType>immediate</attributeAssignActionType>
      <attributeAssignDelegatable>FALSE</attributeAssignDelegatable>
      <attributeAssignActionId>549beae5b8ea4ecb9f9a4c445c86f62a</attributeAssignActionId>
      <attributeAssignActionName>assign</attributeAssignActionName>
      <attributeAssignType>group</attributeAssignType>
      <attributeDefNameId>9f861e04cc794ea0bf79c29c0b116f7b</attributeDefNameId>
      <attributeDefNameName>penn:etc:pspng:provision_to</attributeDefNameName>
      <attributeDefId>48c65c683b224378afed66a90d49dbc6</attributeDefId>
      <attributeDefName>penn:etc:pspng:provision_to_def</attributeDefName>
      <wsAttributeAssignValues>
        <WsAttributeAssignValue>
          <id>dcd4643ba58b4411bd7831d82c67e810</id>
          <valueSystem>pspng_oneprod</valueSystem>
        </WsAttributeAssignValue>
      </wsAttributeAssignValues>
      <createdOn>2018/10/10 14:14:03.421</createdOn>
      <enabled>T</enabled>
      <id>34664c9fd43140839184e061f1ad17db</id>
      <lastUpdated>2018/10/10 14:14:03.421</lastUpdated>
      <ownerGroupId>c1c03f104f34446a802358e5d763ce76</ownerGroupId>
      <ownerGroupName>penn:isc:ait:apps:O365:twoStepProd:o365_two_step_prod</ownerGroupName>
    </WsAttributeAssign>
    <WsAttributeAssign>
      <disallowed>F</disallowed>
      <attributeAssignActionType>immediate</attributeAssignActionType>
      <attributeAssignDelegatable>FALSE</attributeAssignDelegatable>
      <attributeAssignActionId>549beae5b8ea4ecb9f9a4c445c86f62a</attributeAssignActionId>
      <attributeAssignActionName>assign</attributeAssignActionName>
      <attributeAssignType>group</attributeAssignType>
      <attributeDefNameId>9f861e04cc794ea0bf79c29c0b116f7b</attributeDefNameId>
      <attributeDefNameName>penn:etc:pspng:provision_to</attributeDefNameName>
      <attributeDefId>48c65c683b224378afed66a90d49dbc6</attributeDefId>
      <attributeDefName>penn:etc:pspng:provision_to_def</attributeDefName>
      <wsAttributeAssignValues>
        <WsAttributeAssignValue>
          <id>4fb1e45bcfd44b45bfa4acfcdd0f6b2b</id>
          <valueSystem>pspng_oneprod</valueSystem>
        </WsAttributeAssignValue>
      </wsAttributeAssignValues>
      <createdOn>2020/12/21 12:42:41.950</createdOn>
      <enabled>T</enabled>
      <id>0627aae21b2e4df3920ff06bfd77335c</id>
      <lastUpdated>2020/12/21 12:42:41.950</lastUpdated>
      <ownerGroupId>dbfa18c3-a025-47b6-a9a0-be5ac02e8270</ownerGroupId>
      <ownerGroupName>test:testGroup</ownerGroupName>
    </WsAttributeAssign>
  </wsAttributeAssigns>
  <resultMetadata>
    <resultCode>SUCCESS</resultCode>
    <resultMessage>, Found 2 results.  </resultMessage>
    <success>T</success>
  </resultMetadata>
  <responseMetadata>
    <resultWarnings></resultWarnings>
    <millis>108</millis>
    <serverVersion>2.5.44</serverVersion>
  </responseMetadata>
  <wsGroups>
    <WsGroup>
      <extension>o365_two_step_prod</extension>
      <typeOfGroup>group</typeOfGroup>
      <displayExtension>o365_two_step_prod</displayExtension>
      <description>This group identifies users who have o365 two-step enabled.  Note, it might be because they are required or it might be because they opted in or someone assigned them.</description>
      <displayName>penn:isc:ait:apps:O365:twoStepProd:o365_two_step_prod</displayName>
      <name>penn:isc:ait:apps:O365:twoStepProd:o365_two_step_prod</name>
      <uuid>c1c03f104f34446a802358e5d763ce76</uuid>
      <idIndex>346899</idIndex>
      <enabled>T</enabled>
    </WsGroup>
    <WsGroup>
      <extension>testGroup</extension>
      <typeOfGroup>group</typeOfGroup>
      <displayExtension>testGroup</displayExtension>
      <description>testGroup</description>
      <displayName>test:testGroup</displayName>
      <name>test:testGroup</name>
      <uuid>dbfa18c3-a025-47b6-a9a0-be5ac02e8270</uuid>
      <alternateName>testdd:testGroupdd</alternateName>
      <idIndex>197979</idIndex>
      <enabled>T</enabled>
    </WsGroup>
  </wsGroups>
  <wsStems/>
  <wsMemberships/>
  <wsSubjects/>
</WsGetAttributeAssignmentsResults>

################ RESPONSE END ###############


Output template: Index: ${index}: attributeAssignType: ${wsAttributeAssign.attributeAssignType}, owner: ${ownerName}, attributeDefNameName: ${wsAttributeDefName.name}, action: ${wsAttributeAssign.attributeAssignActionName}, values: ${valuesString}, enabled: ${wsAttributeAssign.enabled}, id: ${wsAttributeAssign.id}, available variables: wsGetAttributeAssignmentsResults, grouperClientUtils, index, wsAttributeAssignment
Index: 0: attributeAssignType: group, owner: penn:isc:ait:apps:O365:twoStepProd:o365_two_step_prod, attributeDefNameName: penn:etc:pspng:provision_to, action: assign, values: pspng_oneprod, enabled: T, id: 34664c9fd43140839184e061f1ad17db
Index: 1: attributeAssignType: group, owner: test:testGroup, attributeDefNameName: penn:etc:pspng:provision_to, action: assign, values: pspng_oneprod, enabled: T, id: 0627aae21b2e4df3920ff06bfd77335c
Elapsed time: 943ms
[mchyzer@flash pennGroupsClient-2.5.0]$ 



  • No labels