detachprovisioningtoken deprecated

PACKAGE: open-xchange-admin

NAME

detachprovisioningtoken - detaches a context from a cross-context provisioning token.

SYNOPSIS

detachprovisioningtoken [OPTION]...

DESCRIPTION

This command line tool ends one context's exposure to a cross-context provisioning token. The token stops opening that context; it keeps working for every other context it opens, and is deleted only if this was the last one.

A cross-context token is issued by an administrator standing above the contexts, so the context reached into has no part in it. This is the counterpart: a context can end an access it never granted, the way both sides of a shared account permission can end it. Use listprovisioningtokens(1) with --reaching-into to see which tokens open a context.

This is not a revocation, and not a lasting veto. The token itself survives, and an administrator above the contexts may issue a new token that covers this context again. To end a token everywhere at once, use revokeprovisioningtoken(1).

Detaching a context the token does not open is not treated as an error - the exit code stays 0, and that nothing was detached is reported on the error stream so it is not mistaken for a completed detachment.

In a multi-site installation, run the tool on an admin pod of the site the context belongs to: unlike the site-aware provisioning tools, it does not forward the call to another site.

OPTIONS

-c, --contextid contextid : The context to detach. Mandatory.

--token-id id : The identifier of the token, as listprovisioningtokens(1) with --reaching-into shows it. Mandatory.

-A, --adminuser admin : Administrator name for authentication: the administrator of the context being detached, a reseller administrator owning it, or the master administrator where MASTER_ACCOUNT_OVERRIDE permits it. Optional, depending on your configuration.

-P, --adminpass adminPassword : Administrator password for authentication. Optional, depending on your configuration.

-h, --help : Prints a help text.

--environment : Show info about commandline environment.

--nonl : Remove all newlines (\n) from output.

--responsetimeout : The optional response timeout in seconds when reading data from server (default: 0s; infinite).

EXAMPLES

detachprovisioningtoken -A contextAdmin -P secret -c 1138 --token-id 9b8d4c7fa0e1d2c3b4a596873f2c6a1e

Context 1138 detached from cross-context provisioning token 9b8d4c7fa0e1d2c3b4a596873f2c6a1e; the token no longer opens it

The administrator of context 1138 ends the access of a token it did not issue. Whoever holds that token keeps using it for the other contexts it opens.

SEE ALSO

createprovisioningtoken(1), listprovisioningtokens(1), revokeprovisioningtoken(1), Provisioning over HTTP