Bug 670673 - [doc bug] no data validation for filter in "ipa permissin-add" command
Summary: [doc bug] no data validation for filter in "ipa permissin-add" command
Keywords:
Status: CLOSED DEFERRED
Alias: None
Product: freeIPA
Classification: Retired
Component: Documentation
Version: 2.0
Hardware: Unspecified
OS: Unspecified
low
medium
Target Milestone: ---
Assignee: David O'Brien
QA Contact: Chandrasekar Kannan
URL:
Whiteboard:
Depends On:
Blocks: 670897
TreeView+ depends on / blocked
 
Reported: 2011-01-18 23:19 UTC by Yi Zhang
Modified: 2015-01-04 23:45 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 670897 (view as bug list)
Environment:
Last Closed: 2011-02-02 14:34:31 UTC


Attachments (Terms of Use)

Description Yi Zhang 2011-01-18 23:19:25 UTC
Description of problem:

yi zhang wrote:
> Hi:
>
> The following ipa command returns success:
> ipa permission-add TestPermission --desc "fortest" --attrs=gidunumber
> --permissions=read --filter=cn=
>
> Please notice that "filter" has "cn=" as parameter.
>
> My question is, is this legal? (In another words: is this a bug?)
> Do we do data validation for "filter"? I know that we do validation for
> "attrs" and "memberof".
>
> Thanks!
>

It is a bug but not one I have found a way to fix. I can't find a mechanism in python-ldap to validate a filter. At this point we just have to say "thar be dragons" and let the buyer beware.

rob 

Version-Release number of selected component (if applicable):ipa-server-2.0-0.2011011115gitc778919.fc14.i686


Additional info:
Based on Rob's opinion, i log this as a "doc" bug so we can put it in release-notes (if we end up not fixing it)

Comment 1 Dmitri Pal 2011-02-02 14:32:39 UTC
https://fedorahosted.org/freeipa/ticket/902

Comment 2 Dmitri Pal 2011-02-02 14:34:31 UTC
I am going to close this issue as a bug.
The doc bug is already open and the ticket for 2.1 is filed upstream.
This bug however would not be addressed in 2.0 thus closing as DEFERRED. 
In future the bugs should be risen against a different component.


Note You need to log in before you can comment on or make changes to this bug.