Skip to content

Commit 8c5679e

Browse files
committed
fix: check against memberUid instead of posixGroup
posixGroup might be set up as an auxiliary class, and the oCIS configuration might target a structural class such as groupOfNames. This means that the memberUid attribute might appear in groups configured with groupsOfNames, not just with posixGroup. We'll look for usernames if the group membership is configured as "memberUid" in oCIS regardless of the specific object class for groups.
1 parent 360fd5d commit 8c5679e

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

‎pkg/utils/ldap/identity.go‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -23,9 +23,9 @@ import (
2323
"strings"
2424

2525
identityUser "github.com/cs3org/go-cs3apis/cs3/identity/user/v1beta1"
26-
"github.com/owncloud/reva/v2/pkg/errtypes"
2726
"github.com/go-ldap/ldap/v3"
2827
"github.com/google/uuid"
28+
"github.com/owncloud/reva/v2/pkg/errtypes"
2929
"github.com/pkg/errors"
3030
"github.com/rs/zerolog"
3131
)
@@ -329,8 +329,8 @@ func (i *Identity) IsLDAPUserInDisabledGroup(log *zerolog.Logger, lc ldap.Client
329329
func (i *Identity) GetLDAPUserGroups(log *zerolog.Logger, lc ldap.Client, userEntry *ldap.Entry) ([]string, error) {
330330
var memberValue string
331331

332-
if strings.ToLower(i.Group.Objectclass) == "posixgroup" {
333-
// posixGroup usually means that the member attribute just contains the username
332+
if strings.ToLower(i.Group.Schema.Member) == "memberuid" {
333+
// memberUid means that the member attribute just contains the username
334334
memberValue = userEntry.GetEqualFoldAttributeValue(i.User.Schema.Username)
335335
} else {
336336
// In all other case we assume the member Attribute to contain full LDAP DNs
@@ -467,7 +467,7 @@ func (i *Identity) GetLDAPGroupMembers(log *zerolog.Logger, lc ldap.Client, grou
467467
for _, member := range members {
468468
var e *ldap.Entry
469469
var err error
470-
if strings.ToLower(i.Group.Objectclass) == "posixgroup" {
470+
if strings.ToLower(i.Group.Schema.Member) == "memberuid" {
471471
e, err = i.GetLDAPUserByAttribute(log, lc, "username", member)
472472
} else {
473473
e, err = i.GetLDAPUserByDN(log, lc, member)

0 commit comments

Comments
 (0)