mirror of https://github.com/OpenIdentityPlatform/OpenDJ.git

Valery Kharseko
11 hours ago 85b28b3d0fc05bc49d350a98c07459f4bcb21f43
refs
author Valery Kharseko <vharseko@3a-systems.ru>
Monday, October 5, 2026 14:44 +0200
committer GitHub <noreply@github.com>
Monday, October 5, 2026 14:44 +0200
commit85b28b3d0fc05bc49d350a98c07459f4bcb21f43
tree 91feb9c8cb88757de309a8ecb550e98e7454bae5 tree | zip | gz
parent 6e6cbc7128ebc845f968ae95be36be29a0a05ef8 view | diff
[#1173] Check the references of every managed attribute type of an add and every modification of a modify, not only the first (#1175)

Fixes #1173

## Problem

With `check-references: true`, the Referential Integrity plugin checks
references in its two `doPreOperation` hooks, and both returned after
their first check:

```java
if (result.getResultCode() != ResultCode.SUCCESS)
{
return result;
}
```

A reference that passes yields
`PluginResult.PreOperation.continueOperationProcessing()`, whose result
code is `null`, not `SUCCESS`, so the condition also held for a check
that passed. As a result:

- **add**: only the first managed attribute type was checked. An entry
that did not hold that attribute had none of its references checked,
because an empty attribute list passes too.
- **modify**: only the first ADD or REPLACE modification of a managed
attribute was checked, and the ones after it were not.

## Fix

Both hooks now return early only when processing must stop
(`!result.continueProcessing()`).
`isIntegrityMaintained(List<Attribute>, …)` already worked that way: it
compares with `continueOperationProcessing()`.

## Tests

`ReferentialIntegrityPluginTestCase`, with `check-references` on
`manager` and `seeAlso` below `dc=example,dc=com`, and the data provider
`missingReferenceNextToAnother`: a missing reference in one attribute,
next to a valid reference in the other attribute or alone. Both
attributes take both places, because the order in which the plugin
checks attribute types is an implementation detail.

- `testEnforceIntegrityAddChecksEveryAttributeType`: adding an entry
with a missing reference in either attribute is refused with
`CONSTRAINT_VIOLATION`.
- `testEnforceIntegrityModifyChecksEveryModification`: a modify request
whose second modification adds a missing reference is refused. Its first
modification replaces the other managed attribute with a valid
reference, or, in the rows without one, replaces `description`, which
the plugin does not manage.

The plugin configuration these tests share moved into a helper,
`enableCheckReferences`.

Without the fix, 4 of the 69 tests fail with `expected [Constraint
Violation] but found [Success]`:
- add `[seeAlso, manager]` and `[seeAlso, null]`, because the plugin
checks `manager` first;
- modify `[manager, seeAlso]` and `[seeAlso, manager]`.

The two modify rows without a valid reference passed even before the
fix, since an unmanaged first modification was already skipped; they
guard that case. With the fix the class passes 69/69.

Found while working on #1172 (PR #1174), whose test has to check
`continueProcessing()` for the same reason.
2 files modified
99 ■■■■■ changed files
opendj-server-legacy/src/main/java/org/opends/server/plugins/ReferentialIntegrityPlugin.java 5 ●●●●● diff | view | raw | blame | history
opendj-server-legacy/src/test/java/org/opends/server/plugins/ReferentialIntegrityPluginTestCase.java 94 ●●●●● diff | view | raw | blame | history