-
Notifications
You must be signed in to change notification settings - Fork 12
Open
Description
Reproducible test case:
In Terra:
- Create a group:
deleteable-test-group - Create a workspace:
deleteable-workspace - Share
deleteable-workspacewithdeleteable-test-groupas Readers - Try to delete the group
deleteable-test-group
You will get an error message here:
Error deleting group
Error 409: group deleteable-test-group cannot be deleted because it is a member of
at least 1 other group
Source: sam
The error message here may be accurate from a SAM perspective, but in the Terra UI it is a little confusing. In the example above, the user group created is NOT a member of another group; it is a member of a workspace.
Not sure if SAM can provide a better error message:
Error 409: group deleteable-test-group cannot be deleted because it is a member of
at least 1 other group, workspace, or billing project
or
Error 409: group deleteable-test-group cannot be deleted because it is a member of:
workspace: deleteable-workspace
or something to that effect. Not sure if in all cases providing the specific named workspace, billing account, authorization domain would be information leakage. As Admin of the group, would someone else's use of the group prevent me from deleting the group? How would I chase down the user(s) of the group so that I could clean it up?
Metadata
Metadata
Assignees
Labels
No labels