[Freeipa-devel] [PATCH] 0344-0345 Allow anonymous and all permissions

Martin Kosek mkosek at redhat.com
Fri Jan 3 15:44:38 UTC 2014


On 12/16/2013 12:46 PM, Petr Viktorin wrote:
> Hello,
> The next step in permission effort is small since the groundwork is already done.
> 
> This adds API/CLI for anonymous&all permissions, and disables adding these to
> privileges.
> 
> Ticket: https://fedorahosted.org/freeipa/ticket/4032
> Design: http://www.freeipa.org/page/V3/Anonymous_and_All_permissions
> 

This looks strange

# ipa permission-add anon --type=user --permissions=read --attrs=description
--bindtype=anonymous

# ipa privilege-add-permission foo --perm=ipa: ERROR: invalid 'permission':
cannot add permission "anon" with bindtype "anonymous" to a privilege

(I know, I am nitpicking again).

Otherwise I think the patch is OK.

Martin




More information about the Freeipa-devel mailing list