diff options
author | Rob Crittenden <rcritten@redhat.com> | 2011-05-16 17:39:23 -0400 |
---|---|---|
committer | Rob Crittenden <rcritten@redhat.com> | 2011-05-27 13:51:37 -0400 |
commit | 9cc0754b710500519c6f5fd41a0a0237a43e04b0 (patch) | |
tree | 73534c646557c583290f0b9e070b7d1cf0e553d7 /tests/test_xmlrpc/test_user_plugin.py | |
parent | aa29a8a769c62b07cc4e6d82fc79846505cc9fa3 (diff) | |
download | freeipa-9cc0754b710500519c6f5fd41a0a0237a43e04b0.tar.gz freeipa-9cc0754b710500519c6f5fd41a0a0237a43e04b0.tar.xz freeipa-9cc0754b710500519c6f5fd41a0a0237a43e04b0.zip |
Add option to limit the attributes allowed in an entry.
Kerberos ticket policy can update policy in a user entry. This allowed
set/addattr to be used to modify attributes outside of the ticket policy
perview, also bypassing all validation/normalization. Likewise the
ticket policy was updatable by the user plugin bypassing all validation.
Add two new LDAPObject values to control this behavior:
limit_object_classes: only attributes in these are allowed
disallow_object_classes: attributes in these are disallowed
By default both of these lists are empty so are skipped.
ticket 744
Diffstat (limited to 'tests/test_xmlrpc/test_user_plugin.py')
-rw-r--r-- | tests/test_xmlrpc/test_user_plugin.py | 20 |
1 files changed, 20 insertions, 0 deletions
diff --git a/tests/test_xmlrpc/test_user_plugin.py b/tests/test_xmlrpc/test_user_plugin.py index 597b3b9ba..0be4148a8 100644 --- a/tests/test_xmlrpc/test_user_plugin.py +++ b/tests/test_xmlrpc/test_user_plugin.py @@ -305,6 +305,15 @@ class test_user(Declarative): dict( + desc='Try updating the krb ticket policy of %r' % user1, + command=( + 'user_mod', [user1], dict(setattr=u'krbmaxticketlife=88000') + ), + expected=errors.ObjectclassViolation(info='attribute "krbmaxticketlife" not allowed'), + ), + + + dict( desc='Retrieve %r to verify update' % user1, command=('user_show', [user1], {}), expected=dict( @@ -389,6 +398,17 @@ class test_user(Declarative): dict( + desc='Create user %r with krb ticket policy' % user1, + command=( + 'user_add', [user1], dict(givenname=u'Test', sn=u'User1', + setattr=u'krbmaxticketlife=88000') + ), + expected=errors.ObjectclassViolation(info='attribute "krbmaxticketlife" not allowed'), + ), + + + + dict( desc='Create %r' % user1, command=( 'user_add', [user1], dict(givenname=u'Test', sn=u'User1') |