[Geoserver-devel] [JIRA] (GEOS-9199) Hierarchical LDAP Groups Support

Fernando Miño created an issue

GeoServer / ImprovementGEOS-9199

Hierarchical LDAP Groups Support

Issue Type:

ImprovementImprovement

Assignee:

Fernando Miño

Components:

Security

Created:

03/May/19 4:07 PM

Priority:

MediumMedium

Reporter:

Fernando Miño

Currently Geoserver ldap module support direct user to group role binding, but does not link the user with any upper related group containing (with member attribute) its direct parent group.

Example ldiff, groovydude user being part of groovy-developers group and, by hierarchy, being part of java-developers group at same time:

  dn: cn=java-developers,ou=jdeveloper,dc=springframework,dc=org
  objectclass: top
  objectclass: groupOfNames
  cn: java-developers
  ou: jdeveloper
  member: cn=groovy-developers,ou=groups,dc=springframework,dc=org
  member: cn=scala-developers,ou=groups,dc=springframework,dc=org
  member: uid=javadude,ou=people,dc=springframework,dc=org

   dn: cn=groovy-developers,ou=jdeveloper,dc=springframework,dc=org
  objectclass: top
  objectclass: groupOfNames
  cn: java-developers
  ou: jdeveloper
  member: cn=closure-developers,ou=groups,dc=springframework,dc=org
  member: uid=groovydude,ou=people,dc=springframework,dc=org

  dn: uid=groovydude,ou=people,dc=springframework,dc=org
  objectclass: top
  objectclass: person
  objectclass: organizationalPerson
  objectclass: inetOrgPerson
  cn: Groovy Dude
  sn: Dude
  uid: groovydude
  userPassword: groovydudespassword

Add Comment

Add Comment

Get Jira notifications on your phone! Download the Jira Cloud app for Android or iOS


This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100100-sha1:dbae1b2)

Atlassian logo