URL: https://github.com/freeipa/freeipa/pull/1918 Author: stlaz Title: #1918: [Backport][ipa-4-5] Allow user administrator to change user homedir Action: opened
PR body: """ This PR was opened automatically because PR #1912 was pushed to master and backport to ipa-4-5 is required. """ To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/1918/head:pr1918 git checkout pr1918
From c4d6c6dd184f454a7dd7cf6ceadcab08cdbc1c5d Mon Sep 17 00:00:00 2001 From: Stanislav Laznicka <slazn...@redhat.com> Date: Wed, 9 May 2018 12:26:12 +0200 Subject: [PATCH] Allow user administrator to change user homedir https://pagure.io/freeipa/issue/7427 --- ACI.txt | 2 +- ipaserver/plugins/user.py | 12 ++++++------ 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/ACI.txt b/ACI.txt index 9c7996cc6b..b402aedd81 100644 --- a/ACI.txt +++ b/ACI.txt @@ -361,7 +361,7 @@ aci: (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(obje dn: cn=users,cn=accounts,dc=ipa,dc=example aci: (targetattr = "ipasshpubkey")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=example";) dn: cn=users,cn=accounts,dc=ipa,dc=example -aci: (targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=example";) +aci: (targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homedirectory || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=example";) dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=example aci: (targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=example")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=ipa,dc=example";) dn: cn=users,cn=accounts,dc=ipa,dc=example diff --git a/ipaserver/plugins/user.py b/ipaserver/plugins/user.py index 8866ac0f0a..af8d6a9900 100644 --- a/ipaserver/plugins/user.py +++ b/ipaserver/plugins/user.py @@ -304,12 +304,12 @@ class user(baseuser): 'businesscategory', 'carlicense', 'cn', 'departmentnumber', 'description', 'displayname', 'employeetype', 'employeenumber', 'facsimiletelephonenumber', - 'gecos', 'givenname', 'homephone', 'inetuserhttpurl', - 'initials', 'l', 'labeleduri', 'loginshell', 'manager', 'mail', - 'mepmanagedentry', 'mobile', 'objectclass', 'ou', 'pager', - 'postalcode', 'roomnumber', 'secretary', 'seealso', 'sn', 'st', - 'street', 'telephonenumber', 'title', 'userclass', - 'preferredlanguage', + 'gecos', 'givenname', 'homedirectory', 'homephone', + 'inetuserhttpurl', 'initials', 'l', 'labeleduri', 'loginshell', + 'manager', 'mail', 'mepmanagedentry', 'mobile', 'objectclass', + 'ou', 'pager', 'postalcode', 'roomnumber', 'secretary', + 'seealso', 'sn', 'st', 'street', 'telephonenumber', 'title', + 'userclass', 'preferredlanguage' }, 'replaces': [ '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou || mepmanagedentry || objectclass")(target = "ldap:///uid=*,cn=users,cn=accounts,$SUFFIX")(version 3.0;acl "permission:Modify Users";allow (write) groupdn = "ldap:///cn=Modify Users,cn=permissions,cn=pbac,$SUFFIX";)',
_______________________________________________ FreeIPA-devel mailing list -- freeipa-devel@lists.fedorahosted.org To unsubscribe send an email to freeipa-devel-le...@lists.fedorahosted.org