mirror of
https://github.com/lldap/lldap.git
synced 2026-04-25 08:15:52 +03:00
[GH-ISSUE #583] lldap_admin users cannot modify passwords for other users unless they are also in the lldap_admin #211
Labels
No labels
backend
blocked
bug
cleanup
dependencies
docker
documentation
duplicate
enhancement
enhancement
frontend
github_actions
good first issue
help wanted
help wanted
integration
invalid
ldap
pull-request
question
rust
rust
tests
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/lldap-lldap#211
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @ksladowski on GitHub (May 16, 2023).
Original GitHub issue: https://github.com/lldap/lldap/issues/583
Here are logs from when I tried to change the password of user2 when logged in as myself. My user was a member of lldap_admin and lldap_password_manager. User2 was just a member of lldap_password_manager.
I get a 401 denied error here, but if I make user2 an admin, I can then change user2's password from my account.
@nitnelave commented on GitHub (May 16, 2023):
I see a non-admin user
user: UserId("kevin"), permission: Regulartrying to change another user's passworduser_id: UserId("user2"), which is not allowed.Maybe the current user was added to the admin group while being still logged in and the permissions were not refreshed?