dataflake.org

Home Documentation Software Old Stuff Bug Reporting

Add Entry to: Invalid role in users returned by LDAPUF (Resolved)

Issue Invalid role in users returned by LDAPUF (bug report)
Posted 2004/05/14 by P.-J. Grizel
When you map LDAP groups to Zope roles, all users belonging to a group will get the mapped Zope role (this is ok) and a possibly inexistant role with the LDAP group's cn. This is bad because it can lead to serious security holes (what if, for example, you create a "cn=Manager" group in LDAP ?) and it's not clean to have users around with invalid roles.


Full name
Email address