Hi Juanjo

On 2012-01-09, at 2:40 AM, Juanjo Garcia wrote:

> I've test authenticationFilter is in use when authenticating, but not when 
> retrieving users to fill autocomplete fields. I'm using domains, but all 
> authenticate to the same sql view. I've set up authenticationFIlter for every 
> domain, which doesn't matter for authentication because all the users on the 
> view are allowed, but I expected to filter the autocomplete field, but it 
> doesn't work.

As as wrote, you need the behaviour of the "filter" parameter, which is only 
available for LDAP sources. You can fill a feature request on the BTS if you 
want (http://www.sogo.nu/bugs/).

> Juanjo Garcia <jua...@digitalvalue.es>
> Digital Value S.L. http://www.digitalvalue.es
> Tel. 96.316.20.89
> Fax 96.373.85.07
> Ausias March 104, Accs. - Valencia -
> El 05/01/12 15:42, Francis Lachapelle escribió:
>> Hi Paul, Juanjo
>> 
>> On 2011-12-21, at 4:16 AM, Paul van der Vlis wrote:
>> 
>> 
>>> Op 20-12-11 19:33, Juanjo Garcia schreef:
>>> 
>>>> I'm using authenticationFilter on mysql and it works fine with numerical
>>>> clauses, but I've seen that this clause is not in use when filling 
>>>> autocomplete
>>>> fields for ACL, mostly because you don't want to give permissions to 
>>>> anyone who
>>>> can't access, and because it will offer a way to limit the users shown in 
>>>> this
>>>> field.
>>>> 
>>>> Showing all users on autocomplete fields is also a security problem, 
>>>> because
>>>> one user can see all usernames, and, in my case, their email addresses.
>>>> 
>> What you need is the "filter" parameter available for LDAP sources but not 
>> yet SQL sources. Adding support for this parameter should be easy.
>> 
>> 
>>> For me this is a problem too. When you have one firm what uses Sogo it's
>>> no point, but when different little organisations or private persons are
>>> using it on one installation, it's not nice. I would like a way to
>>> turn-off the autocompletion.
>>> 
>>> Maybe it's possible now to make groups of users. where the users can see
>>> only the others of the group. But I don't know how to realize that, and
>>> I am afraid it's a bit to complex for my situation.
>>> 
>> You should instead activate multi-domains in your configuration.
>> 
>> 
>> Francis

--
flachape...@inverse.ca :: +1.514.755.3640 :: http://www.inverse.ca
Inverse :: Leaders behind SOGo (http://sogo.nu) and PacketFence 
(http://packetfence.org)

-- 
users@sogo.nu
https://inverse.ca/sogo/lists

Reply via email to