directory-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Stefan Zoerner (JIRA)" <j...@apache.org>
Subject [jira] Updated: (DIRSERVER-606) ou=users, ou=system - user cannot see their own entry
Date Fri, 21 Apr 2006 08:36:06 GMT
     [ http://issues.apache.org/jira/browse/DIRSERVER-606?page=all ]

Stefan Zoerner updated DIRSERVER-606:
-------------------------------------

    Attachment: patch.txt

This small patch (1 line) allows users to search their own entry. It changes a condition within
the isSearchable method of OldAuthorizationService. 

There is still a problem left, if the DN of the user contains uppercase letters, or if s/he
uses uppercase letters in the bind DN. In these cases, the issue still exists. The reason
for this is the equals method of org.apache.directory.shared.ldap.name.LdapName, which is
used frequently in OldAuthorizationService, and which is case sensitive.

Two options here:
a) modify equals() in LdapName to ignore case
b) perform special checks in OldAuthorizationService which ignore case

> ou=users, ou=system - user cannot see their own entry
> -----------------------------------------------------
>
>          Key: DIRSERVER-606
>          URL: http://issues.apache.org/jira/browse/DIRSERVER-606
>      Project: Directory ApacheDS
>         Type: Bug

>     Versions: 1.0-RC1
>  Environment: JDK 1.4.1
> Tried both JXplorer, and from ACEGI security
>     Reporter: Marc Batchelor
>     Assignee: Stefan Zoerner
>     Priority: Critical
>  Attachments: patch.txt
>
> User binds to ApacheDS as a user under ou=users, ou=system. The user cannot see their
own entry to get their own attributes.
> Documentation states: Users cannot see other user entries under the 'ou=users,ou=system'
entry.
> Agreed and understood. But, the user, after binding with the directory, cannot even find
their own entry to get their own attributes. 

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators:
   http://issues.apache.org/jira/secure/Administrators.jspa
-
For more information on JIRA, see:
   http://www.atlassian.com/software/jira


Mime
View raw message