[GH-ISSUE #227] lldap_readonly group is able to reset password #78

Closed
opened 2026-02-27 08:15:06 +03:00 by kerem · 1 comment
Owner

Originally created by @adepssimius on GitHub (Jul 8, 2022).
Original GitHub issue: https://github.com/lldap/lldap/issues/227

The group name is confusing since the readonly group should not be able to write anything.

Desired functionality is to follow the principle of least privilege so that applications may update passwords without a user account that is able to manage users and groups.

Additionally, the ability to have a true read only group would be useful for applications that do not have the functionality to change the password.

Originally created by @adepssimius on GitHub (Jul 8, 2022). Original GitHub issue: https://github.com/lldap/lldap/issues/227 The group name is confusing since the readonly group should not be able to write anything. Desired functionality is to follow the principle of least privilege so that applications may update passwords without a user account that is able to manage users and groups. Additionally, the ability to have a true read only group would be useful for applications that do not have the functionality to change the password.
kerem closed this issue 2026-02-27 08:15:07 +03:00
Author
Owner

@adepssimius commented on GitHub (Jul 8, 2022):

Proposed solution.
image

<!-- gh-comment-id:1179108303 --> @adepssimius commented on GitHub (Jul 8, 2022): Proposed solution. ![image](https://user-images.githubusercontent.com/5257052/178022269-bc60d597-467e-420a-bc2c-82f5be340304.png)
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/lldap-lldap#78
No description provided.