8000 Improving LDAP-Setting-Docs required? · Issue #77 · wekan/ldap · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
This repository was archived by the owner on Dec 22, 2024. It is now read-only.

Improving LDAP-Setting-Docs required? #77

Closed
daMihe opened this issue Mar 14, 2020 · 5 comments
Closed

Improving LDAP-Setting-Docs required? #77

daMihe opened this issue Mar 14, 2020 · 5 comments

Comments

@daMihe
Copy link
daMihe commented Mar 14, 2020

Currently, the examples are a bit mixed up (maybe some parameters have been renamed) and some doc-strings are missing. However, it was hard for me to set wekan-ldap-settings correctly as description was missing partly or not fully clear. I would share what i've learned in form of some docstrings. Where is the right place for that?

@xet7
Copy link
Member
xet7 commented Mar 14, 2020

@daMihe

You can add pull request to change these files:

Also, if you have any additional improvements to wiki page https://github.com/wekan/wekan/wiki/LDAP you can add them as comments to this issue. I added a link to this issue at top of that wiki page.

@daMihe
Copy link
Author
daMihe commented Mar 14, 2020

Wekan seems to make the search as the user currently logged in, even if a separate user is used for searching users. This results in the requirement that every authenticated user has to have at least the right to search the ldap tree and to read the wekan-relevant groups.

This is verified using OpenLDAP allowing search to all authenticated users in whole tree and read for corresponding groups.

@daMihe
Copy link
Author
daMihe commented Mar 14, 2020

Thank you for the fast process of reviewing and merging!

@daMihe daMihe closed this as completed Mar 14, 2020
@xet7
Copy link
Member
xet7 commented Mar 14, 2020

From @daMihe

Wekan seems to make the search as the user currently logged in, even if a separate user is used for searching users. This results in the requirement that every authenticated user has to have at least the right to search the ldap tree and to read the wekan-relevant groups.

This is verified using OpenLDAP allowing search to all authenticated users in whole tree and read for corresponding groups.

If that is incorrect behaviour, you could look at LDAP code https://github.com/wekan/wekan/tree/master/packages/wekan-ldap about can you fix that. I know very little about how LDAP works, or should work.

@daMihe
Copy link
Author
daMihe commented Mar 14, 2020

Hm - let's say the behavior is a bit... strange. If you know it, it's not so hard to work around. However i'll take a look whether i can do a simple fix these days.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants
0