Bug 245830 - Get Effective Rights Control slightly broken
Summary: Get Effective Rights Control slightly broken
Keywords:
Status: CLOSED DUPLICATE of bug 437525
Alias: None
Product: Red Hat Directory Server
Classification: Red Hat
Component: Security - Access Control (ACL)
Version: 8.0
Hardware: All
OS: Linux
medium
low
Target Milestone: DS8.1
: ---
Assignee: Rich Megginson
QA Contact: Chandrasekar Kannan
URL:
Whiteboard:
Depends On:
Blocks: 249650
TreeView+ depends on / blocked
 
Reported: 2007-06-26 21:48 UTC by Bob Lord
Modified: 2015-01-04 23:27 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-12-02 18:23:25 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Pete Rowley 2007-06-26 21:48:16 UTC
Description of problem:
The get effective rights control returns access control status for attributes
existing in an entry. However this means that access control status cannot be
determined for attribute types that are allowed but not present on an entry, so
for example, a gui interface cannot predetermine if a user is allowed to add the
first value for an attribute and therefore should display the field for
modification. This would be a nice thing for freeIPA.

Version-Release number of selected component (if applicable):


How reproducible:

always

Steps to Reproduce:
1. use effective rights control
2.
3.
  
Actual results:

no mention of allowed but not existing attributes

Expected results:

The ability to get ionformation on these attribute types - possibly by way of a
flag for the control.

Additional info:

Comment 4 Rich Megginson 2008-12-02 17:27:02 UTC
This has been fixed, correct?

Comment 5 Noriko Hosoi 2008-12-02 18:05:25 UTC
(In reply to comment #4)
> This has been fixed, correct?

Yes, one of these cases on the wiki page should cover the RFE, I think.
2-2. requester: tuser0, subject user: tuser0: tuser0 shows tuser0's effective rights of the user given attribute list, which do not exist in the entries. tuser0 is allowed to see the effective rights of the entries that tuser0 can read/search. 

2-3. requester: tuser0, subject user: tuser0: tuser0 shows tuser0's effective rights of all the available attributes associated with the entry's objectclasses, which values may or may not exist. tuser0 is allowed to see the effective rights of the entries that tuser0 can read/search.

http://directory.fedoraproject.org/wiki/Get_Effective_Rights_for_non-present_attributes#2._Cases_newly_supported

This is the bug I used to work on GER enhancement.
 Bug 437525 -  GER: allow GER for non-existing entries

Can we mark this bug as Duplicate of 437525?

Comment 6 Rich Megginson 2008-12-02 18:23:25 UTC

*** This bug has been marked as a duplicate of bug 437525 ***


Note You need to log in before you can comment on or make changes to this bug.