Repository navigation
Conversation
…ns and tolerate stored ones A temporal constraint whose duration is not a valid ISO 8601 interval (e.g. its end is before its start) made the effectiveRoles onRetrieve script throw, so every read and update of the user failed with 500. The admin UI produced such a value itself: an empty end date was sent as the current time. - Reject such a constraint with 400 when a role grant or a role is written - Skip, with a warning, an invalid constraint that is already stored when calculating effective roles, expired constraints and schedules - Admin UI: require both dates with the end after the start before a role or a role member with a temporal constraint can be saved Fixes OpenIdentityPlatform#250
vharseko
force-pushed
the
issue-250-temporal-constraints
branch
from
October 6, 2026 15:23
2f61541 to
779494c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #250
Problem
effectiveRolesis a virtual property returned by default, so itsonRetrievescript runs on every read and every update of a user. The script parses each temporal constraint duration with Joda'sInterval.parse, which throws on an interval whose end is before its start. Nothing validated the duration when a grant or a role was written, so once such a value was stored the user could neither be read nor fixed throughmanaged/user(500effectiveRoles onRetrieve script encountered exception).The admin UI produced such a value itself: with a start date in the future and an empty end date,
convertToIntervalStringsent the current time as the end. Replaying that exact request on a build without the fix:POST managed/role/<id>/membersreturns 500 after the grant is already stored, and from then onGET managed/user/<id>and even the user's grant list return 500.Changes
Reject on write (400 instead of storing the value)
DateUtil.isValidInterval(String): true only ifInterval.parseaccepts the string (null, garbage and reversed intervals are invalid;datetime/periodforms stay valid).RelationshipValidator.validateTemporalConstraints: grant constraints must be an array of at most one constraint with a validduration. Called fromvalidateRelationship(before the managed object is written and before virtual properties are computed) and fromRelationshipProvider.convertToRepoObject(direct writes to a relationship endpoint), replacing the existing "Only 1 temporal constraint" check there.conditionalRoles.roleCreate/roleUpdate: the same check for a role's own temporal constraints.Tolerate values that are already stored
effectiveRoles.processConstraintsandtemporalConstraints.areConstraintsExpiredskip an invalid constraint with a warning; it never grants the role.postOperation-roles.createJobsForConstraintlogs and creates no schedules for an invalid duration instead of failing a request whose resource is already stored.Admin UI
TemporalConstraintsUtils.isValidIntervalrequires both dates and the end after the start;TemporalConstraintsFormViewshows an error under the end date, andEditRoleView(Save) andMembersDialog(Add) stay disabled while the form is invalid.EditRoleView.savealso refuses to send an invalid form.Testing
DateUtilTest,RelationshipValidatorTest(valid / invalid_refProperties), allopenidm-coretests.effectiveRolesTest,temporalConstraintsTest,conditionalRolesTestcover reversed and unparseable durations; without theeffectiveRoles.jschange the new test fails with the exception from the issue.testRunner.jsnow provides a no-oplogger, as the scripts log through the binding OpenIDM supplies at runtime.isValidInterval(125 tests, 0 failed); eslint clean on the changed UI files.