Bug 786629 - [ipa webui] permission with filter or subtree does not allow attr to be specified
Summary: [ipa webui] permission with filter or subtree does not allow attr to be speci...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: ipa
Version: 6.2
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: Martin Prpič
QA Contact: IDM QE LIST
URL:
Whiteboard:
Depends On: 783536
Blocks: 819997
TreeView+ depends on / blocked
 
Reported: 2012-02-01 23:48 UTC by Dmitri Pal
Modified: 2012-05-10 17:10 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Because a permission does not provide write access to an entry, delegation does not work as expected. The 389 Directory Server (389-ds) distinguishes access between entries and attributes. For example, an entry can be granted add or delete access, whereas an attribute can be granted read, search, and write access. To grant write access to an entry, the list of writable attributes needs to be provided. The filter, subtree, and other options are used to target those entries which are writable. Attributes define which part(s) of those entries are writable. As a result, the list of attributes will be writable to members of the permission.
Clone Of: 783536
: 819997 (view as bug list)
Environment:
Last Closed: 2012-05-10 17:10:40 UTC
Target Upstream Version:


Attachments (Terms of Use)

Comment 3 Rob Crittenden 2012-04-02 15:45:12 UTC
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
Cause: A permission doesn't provide write access to an entry

Consequence: Delegation does not work as expected

Fix: 389-ds distinguishes access between entries and attributes. One grants add or delete access to an entry but read, search and write access to an attribute. To grant write access on an entry the list of writable attributes needs to be provided. The filter, subtree, etc. are used to target those entries which are writable. Attributes define which part(s) of those entries are writable.

Result: The list of attributes will be writable to members of the permission.

Comment 4 Martin Prpič 2012-04-15 12:57:40 UTC
    Technical note updated. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    Diffed Contents:
@@ -1,7 +1 @@
-Cause: A permission doesn't provide write access to an entry
+Because a permission does not provide write access to an entry, delegation does not work as expected. The 389 Directory Server (389-ds) distinguishes access between entries and attributes. For example, an entry can be granted add or delete access, whereas an attribute can be granted read, search, and write access. To grant write access to an entry, the list of writable attributes needs to be provided. The filter, subtree, and other options are used to target those entries which are writable. Attributes define which part(s) of those entries are writable. As a result, the list of attributes will be writable to members of the permission.-
-Consequence: Delegation does not work as expected
-
-Fix: 389-ds distinguishes access between entries and attributes. One grants add or delete access to an entry but read, search and write access to an attribute. To grant write access on an entry the list of writable attributes needs to be provided. The filter, subtree, etc. are used to target those entries which are writable. Attributes define which part(s) of those entries are writable.
-
-Result: The list of attributes will be writable to members of the permission.


Note You need to log in before you can comment on or make changes to this bug.