[IOTDM-69] Compliance - IoTDM is not validating "acco/acw" element of ACP Created: 06/Mar/17 Updated: 19/Oct/17 |
|
| Status: | Open |
| Project: | iotdm |
| Component/s: | General |
| Affects Version/s: | unspecified |
| Fix Version/s: | None |
| Type: | Bug | ||
| Reporter: | Anil Pandey | Assignee: | Unassigned |
| Resolution: | Unresolved | Votes: | 0 |
| Labels: | None | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Environment: |
Operating System: All |
||
| External issue ID: | 7904 |
| Description |
|
IoTDM is not doing validation on "allowed number of elements" & "respective value" While creating ACP with optional attribute - "accessControlContexts/accessControlWindow" "accessControlContexts/accessControlWindow" is of type "m2m:scheduleEntry" As per spec - "m2m:scheduleEntry" support following elements and values - Table 7.4.9.1-4: Definition of m2m:scheduleEntry string format ====================================================================== Actual behavior of IoTDM - Currently, IoTDM is allowing me to set more then 7 values without doing any range check on the value. Following is what IoTDM is returning for a configured ACP. {"m2m:acp":{"ct":"20170306T092810","ty":1,"pv":{"acr":[{"acco":[ {"acw":"0-69 0-59 0-24 1-32 1-13 0-7 2017-2018 1"}],"acor":["admin"],"acop":63}]},"ri":"01gr","lt":"20170306T092810","pi":"/InCSE1/01ge","pvs":{"acr":[{"acco":[ {"acw":"* * * * * * * * 2017-2018"}],"acor":["admin"],"acop":63}]},"rn":"Acp3.03.01","et":"29991231T111111"}} Please notice following values - "acw":"0-69 0-59 0-24 1-32 1-13 0-7 2017-2018 1" Expected behavior of IoTDM - |