When setting the provisioning from LDAP to Drupal Mappings, if you select an [ou] which contains an uppercase letter to map to Field: Roles then this will always cause an error, as Drupal does not allow the creation of roles with uppercase machine names.

Login will be successful for the user and no errors are thrown when creating the account and user__roles is populated as expected.

Issue will manifest as:
Error: Call to a member function label() on null in Drupal\user\Plugin\views\field\Roles->preRender()
when trying to view admin/people. If you navigate to the new user via their ID and edit them the role has not been assigned.

I have workaround this by altering the Drupal User Processor with the attached small patch, but not sure if this is the right way to go about things??

Comments

salaDDodger created an issue. See original summary.

grahl’s picture

Hi salaDDodger

Thanks for that patch and the detailed description of your issue.

I will need to investigate further to figure out where this also might be relevant.

grahl’s picture

Assigned: Unassigned » grahl
grahl’s picture

Status: Active » Postponed
Issue tags: -D8 stable release blocker

Hi salaDDodger

We might need an optional lowercase transformation in general to fix issues such as yours. I don't want to hardcode this property since it will not provide a robust mapping, e.g. dashes and such would not transform into valid role machine names.

I'm marking this as postponed since I'm not convinced that we should follow this route and I'm actually closer to just excluding that property from being selectable but am leaving it available for now.

For your particular scenario I recommend using the authorization module. That way you can flexibly map your roles as needed and just mapping roles directly is definitely not recommended. (Or do it with with a hook into ldap_user and custom code if that's not applicable.)

grahl’s picture

Assigned: grahl » Unassigned
grahl’s picture

Status: Postponed » Closed (won't fix)

Group assignment should not be done via user mapping and will not be supported. If absolutely required, hooks are available for using / transforming such data.