Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-32199

system fails to ensure unique OAuth client_id

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Open
    • Priority: Minor
    • Resolution: Unresolved
    • Affects Version/s: 11.1
    • Fix Version/s: None
    • Component/s: OAuth

      Description

      When creating an OAuth client via REST, I am able to set my client_id value to a value that already exists in the system (though it bears a unique "id" property... an increment from the previous id). Thereafter, multiple clients exist with the same client_id, resulting in an inconsistent state, and the inability to delete either one of them via REST. It does remain possible to delete them via JSF Admin UI.

      When attempting to delete one of the duplicate clients via WebUI, we see:
      ERROR: An error occurred while deleting the client.

      and a HTTP 500 exception.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              smiller Stuart Miller
              Participants:
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated: