# Identity Attribute Rule Problem

**URL:** <https://developer.sailpoint.com/discuss/t/identity-attribute-rule-problem/74003>\
**Category:** SHF Discussion and Questions\
**Tags:** identity-security-cloud, rules\
**Created:** [July 24, 2024, 8:28pm UTC](https://developer.sailpoint.com/discuss/t/identity-attribute-rule-problem/74003 "2024-07-24T20:28:39Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajithkumarreddykallu](https://avatars.discourse-cdn.com/v4/letter/a/9fc29f/32.png) [@ajithkumarreddykallu](https://developer.sailpoint.com/discuss/u/ajithkumarreddykallu)\
**Post date:** [July 24, 2024, 8:28pm UTC](https://developer.sailpoint.com/discuss/t/identity-attribute-rule-problem/74003/1 "2024-07-24T20:28:39Z")

</div>

Hi Team,

I am facing issue while validating identity attribute rule as below

```auto
<?xml version='1.0' encoding='UTF-8'?>

<!DOCTYPE Rule PUBLIC "sailpoint.dtd" "sailpoint.dtd">

<Rule name="PopulateLCS" type="IdentityAttribute">

<Description>Calculates LCS based on start and end dates.</Description>

<Source><![CDATA[

import java.text.SimpleDateFormat;

import java.util.Date;

import java.util.Calendar;

import sailpoint.tools.GeneralException;

import java.util.Iterator;

import sailpoint.object.*;

import java.util.ArrayList;

import sailpoint.api.*;

import sailpoint.object.*;

import java.util.Iterator;

import java.util.List;

import org.apache.commons.lang.StringUtils;

String orgID = identity.getAttribute("originalId");

String empNumber = identity.getAttribute("identificationNumber");

if (orgID != null && empNumber != null){

if (orgID != empNumber){

//String samAccount = idn.getIdentityById("orgID").getSamaccountname();

sailpoint.rule.Identity foundIdentity = idn.getIdentityById("orgID");

String samaccount = foundIdentity.getSamaccountname();

if (samAccount == null && samAccount.isEmpty()){

return prehire;

}

else

{

return prehire-conversion;

}

}

}

// Date format we expect dates to be in (ISO8601)

SimpleDateFormat dateFormat = new SimpleDateFormat("MM-dd-yyyy");

if (identity.getAttribute("onLeave").equals("1")) {

return "loa";

}

// Parse the start date from the identity, and put in a Date object.

Date startDate = null;

if (identity.getAttribute("startDate") != null || !(identity.getAttribute("startDate").isEmpty())) {

startDate = dateFormat.parse(identity.getAttribute("startDate"));

} else return "inactive";

// Define a date for today

Date today = new Date();

// Calculate 7 days before start date

Calendar cal = Calendar.getInstance();

cal.setTime(startDate);

cal.add(Calendar.DAY_OF_YEAR, -7);

Date prehireDate = cal.getTime();

if (identity.getAttribute("endDate") == null || identity.getAttribute("endDate").isEmpty()) {

if ((today.equals(prehireDate)) || today.after(prehireDate) && today.before(startDate)) {

return "prehire";

} else if (today.equals(startDate) || today.after(startDate)) {

return "active";

}

return "inactive";

}

// Parse the end date from the identity, and put in a Date object.

Date endDate = null;

if (identity.getAttribute("endDate") != null) {

endDate = dateFormat.parse(identity.getAttribute("endDate"));

}

// Calculate 91 days after end date

cal.setTime(endDate);

cal.add(Calendar.DAY_OF_YEAR, 91);

Date deleteDate = cal.getTime();

// Calculate lifecycle state based on the attributes.

if ((today.equals(prehireDate)) || today.after(prehireDate) && today.before(startDate)) {

return "prehire";

} else if ((today.equals(endDate)) || (today.equals(startDate)) || (today.after(startDate) && today.before(endDate))) {

return "active";

} else if ((today.after(endDate) && today.before(deleteDate))) {

return "disabled";

} else if (identity.getAttribute("legalHold").equals("Y") || identity.getAttribute("cloudLifecycleState").equals("immediatetermination")){

return identity.getAttribute("cloudLifecycleState");

} else if (today.equals(deleteDate) || today.after(deleteDate)) {

return "delete";

}

// If we haven't calculated a state already, return inactive.

return "inactive";

]]></Source>

</Rule>

```

Can anyone suggest me how to fix this issue

 ![undefined](https://global.discourse-cdn.com/sailpoint/original/2X/0/081f44db9a48d20353a9c56eb85d42ccc29dd594.png)

---

<div class="post-metadata">

**Author:** ![Sriindugula](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sriindugula/32/14041_2.png) [@Sriindugula](https://developer.sailpoint.com/discuss/u/Sriindugula)\
**Post date:** [July 24, 2024, 11:59pm UTC](https://developer.sailpoint.com/discuss/t/identity-attribute-rule-problem/74003/2 "2024-07-24T23:59:28Z")

</div>

Hi @ajithkumarreddykallu

There are multiple errors in the rule

1. Already there is identity as input argument for the rule, getting an identity again is not required which is below ( and it is not correct in the rule ) you can use identity as you used in starting of the rule (remove below line from rule)

sailpoint.rule.Identity foundIdentity = idn.getIdentityById(“orgID”);

1. Is samAccountName an identity attribute or account attribute?? If it is identity attribute below line is incorrect

String samaccount = foundIdentity.getSamaccountname();

It should be like

String samaccount = identity.getAttribute(“samAccountName”);

1. As you are returning string it should be as below  
return “prehire”;  
not  
return prehire;

2. Same as point 3 for return prehire-conversion;  
It should be return “prehire-conversion”;

Hope this helped!!!

Thanks

---

<div class="post-metadata">

**Author:** ![nikhlesh21](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/nikhlesh21/32/11800_2.png) [@nikhlesh21](https://developer.sailpoint.com/discuss/u/nikhlesh21)\
**Post date:** [July 25, 2024, 6:45am UTC](https://developer.sailpoint.com/discuss/t/identity-attribute-rule-problem/74003/3 "2024-07-25T06:45:32Z")

</div>

HI @ajithkumarreddykallu,

Is there any specific reason why you could not use Transform to calculate the LCS?

Thanks.

---

<div class="post-metadata">

**Author:** ![ajithkumarreddykallu](https://avatars.discourse-cdn.com/v4/letter/a/9fc29f/32.png) [@ajithkumarreddykallu](https://developer.sailpoint.com/discuss/u/ajithkumarreddykallu)\
**Post date:** [July 31, 2024, 2:44pm UTC](https://developer.sailpoint.com/discuss/t/identity-attribute-rule-problem/74003/4 "2024-07-31T14:44:00Z")

</div>

Nope. we thought rule was better. The only problem is sailpoint.rule.Identity foundIdentity = idn.getIdentityById(“orgID”);

We need this identity which is different to normal identity.

ORGID has different UID value.

---

<div class="post-metadata">

**Author:** ![ajithkumarreddykallu](https://avatars.discourse-cdn.com/v4/letter/a/9fc29f/32.png) [@ajithkumarreddykallu](https://developer.sailpoint.com/discuss/u/ajithkumarreddykallu)\
**Post date:** [July 31, 2024, 2:53pm UTC](https://developer.sailpoint.com/discuss/t/identity-attribute-rule-problem/74003/5 "2024-07-31T14:53:39Z")

</div>

Hello

Thank you for the response.

Sailpoint.rule.Identity foundIdentity = idn.getIdentityById(“orgID”);

We need to get sam account name of Identity with UID org ID. So we need this.  
We can change prehire and pre-hire conversion.

Any help will be appreciated

---

<div class="post-metadata">

**Author:** ![varshini303](https://avatars.discourse-cdn.com/v4/letter/v/9d8465/32.png) [@varshini303](https://developer.sailpoint.com/discuss/u/varshini303)\
**Post date:** [July 31, 2024, 7:03pm UTC](https://developer.sailpoint.com/discuss/t/identity-attribute-rule-problem/74003/6 "2024-07-31T19:03:33Z")

</div>

Hello @ajithkumarreddykallu

I assume that you have an identity attribute with name **samAccountName** mapped to the AD source’s sAMAccountName account attribute, if not you can create one identity attribute with mapping.

As per java docs, the _sailpoint.rule.Identity_ interface does not provide any method like _getAtrribute_(“someIdentityAttribute”) or other few methods unlike the _sailpoint.object.Identity_ class which provides them.

With the available methods in _sailpoint.rule.Identity_, maybe you can try this for you requirement:

Make use of the getAttributes() for the found identity. I am exactly not aware of the key-value contents of the map though.

The snippet looks like:

```auto
Sailpoint.rule.Identity foundIdentity = idn.getIdentityById(“orgID”);
Map attributesMap = foundIdentity.getAttributes();

String samAccount = attributesMap.get("samAccountName");

```

Also, Make sure to use the variable names correctly to avoid any undefined variable name errors.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [September 29, 2024, 7:04pm UTC](https://developer.sailpoint.com/discuss/t/identity-attribute-rule-problem/74003/7 "2024-09-29T19:04:11Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
