Back to bug 1008021

Who When What Removed Added
Nathan Kinder 2013-12-18 15:42:21 UTC Status NEW POST
Ann Marie Rubin 2014-02-04 19:51:10 UTC Blocks 1061410
RHEL Program Management 2014-03-16 19:36:26 UTC Status POST CLOSED
Resolution --- WONTFIX
Last Closed 2014-03-16 15:36:26 UTC
Nathan Kinder 2014-03-17 01:26:49 UTC Status CLOSED POST
Resolution WONTFIX ---
Keywords Reopened
Noriko Hosoi 2014-06-18 20:45:37 UTC Status POST MODIFIED
CC nhosoi
Fixed In Version 389-ds-base-1.2.11.15-34.el6
errata-xmlrpc 2014-06-18 22:02:24 UTC Status MODIFIED ON_QA
Viktor Ashirov 2014-06-26 17:04:59 UTC Status ON_QA VERIFIED
CC vashirov
thierry bordaz 2014-06-27 13:57:24 UTC CC tbordaz
thierry bordaz 2014-06-27 14:10:13 UTC Doc Text Cause: using self entry access aci, if an operation evaluates access on several entries (search returning several entries), the result of a granted access for an entry is cached and can erroneously be reused for all entries

Consequence: A bound client can retrieve entries/attributes he should not be allowed or can fail to retrieve entries/attributes he should be allowed

Fix: Some access are granted per entry, make sure that if granted access is cached it is purged for the next entry

Result: A self access aci, should be evaluated evaluated for each entry
Lubos Kocman 2014-07-22 17:07:22 UTC Depends On 1122165
John Shortt 2014-07-22 17:57:00 UTC Depends On 1122165
errata-xmlrpc 2014-10-14 07:50:16 UTC Status VERIFIED CLOSED
Resolution --- ERRATA
Last Closed 2014-03-16 15:36:26 UTC 2014-10-14 03:50:16 UTC
Simon Pichugin 2020-09-13 20:28:24 UTC Link ID Github 389ds/389-ds-base/issues/668

Back to bug 1008021