As I came into work this morning my colleague, on a phone call, glanced up and said, "Hold on, he just walked in." Oh great.
The user was telling us that our Enterprise Confluence (4.3.1) installation became over-subscribed. Not a big deal, or at least it shouldn't be. It turns out that Confluence does not just disable the user who joins. No, it disables editing for *all users* until the oversubscription is fixed.
Why should one innocent user be able to create an enterprise-wide crisis? (Yes, Confluence does serve an important function in our enterprise--at the moment).
OK fine, I'll just inactivate the user who is over-subscribed. Oh wait, that feature is busted in Confluence when LDAP integration is enabled, because Confluence expects to be able to edit your enterprise's AD in order to disable users, and no combination of user-directory checkbox settings will disavow it of its misguided notion that AD write access is not necessary.
What I *CAN* do is directly edit the Confluence database to set the desired users 'active' to F (false). Finding these users requires a complex query that must be obtained from Atlassian's legendary support. To wit:
select distinct(u.user_name),u.active,d.active,u.updated_date from cwd_user u
inner join cwd_membership m on m.child_user_id=u.id
inner join cwd_group g on m.parent_id=g.id
inner join cwd_directory d on d.id=u.directory_id
inner join spacepermissions p on g.group_name=p.permgroupname
where u.active='T' and d.active='T' and p.permtype='USECONFLUENCE'
order by u.updated_date desc;
This whittled down the 2,702 rows in cwd_user to the 505 that actually matter. Unfortunately, after updating the over-subscribed users, I have to restart Confluence in order for it to notice.
Here's some salt for the wound: I get plenty of notifications from Confluence that my license is getting close to expiration, and I need to pay more money. But I got not a peep's worth warning that the next user to log into Confluence is going to precipitate a hostage crisis. It's the users who have to let us know.
Why didn't I just pay more money earlier and sidestep the whole fire drill? Because Atlassian's licensing model jumps from 500 users to 2,000 users; there is no in-between.
What am I asking for?
1) Fix Confluence's behavior when a user over-subscribes, so that only the over-subscribed user is affected. The current behavior is inexcusable.
2) Fix user disabling so that it works from the web UI.
3) Send notifications when the active user count is getting close to the limit.
-chris