Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
S
slapos.core
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Analytics
Analytics
CI / CD
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
Léo-Paul Géneau
slapos.core
Commits
86e249bf
Commit
86e249bf
authored
Oct 22, 2012
by
Łukasz Nowak
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Security fix: check Assignment in case of Person.
parent
8c89b14e
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
5 additions
and
0 deletions
+5
-0
master/product/SlapOS/SlapOSShadowAuthenticationPlugin.py
master/product/SlapOS/SlapOSShadowAuthenticationPlugin.py
+5
-0
No files found.
master/product/SlapOS/SlapOSShadowAuthenticationPlugin.py
View file @
86e249bf
...
...
@@ -44,6 +44,7 @@ from Products.ERP5Security.ERP5UserManager import SUPER_USER
from
ZODB.POSException
import
ConflictError
from
Products.ERP5Security.ERP5GroupManager
import
ConsistencyError
,
NO_CACHE_MODE
from
Products.ERP5Type.Cache
import
CachingMethod
from
Products.ERP5Security.ERP5UserManager
import
getValidAssignmentList
# some usefull globals
LOGGABLE_PORTAL_TYPE_LIST
=
[
"Person"
,
"Computer"
,
"Software Instance"
]
...
...
@@ -130,6 +131,10 @@ class SlapOSShadowAuthenticationPlugin(BasePlugin):
user_list
=
self
.
getUserByLogin
(
login
)
if
len
(
user_list
)
!=
1
:
return
None
user
=
user_list
[
0
]
if
user
.
getPortalType
()
==
'Person'
:
if
len
(
getValidAssignmentList
(
user
))
==
0
:
return
None
return
(
login
,
login
)
def
getUserByLogin
(
self
,
login
):
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment