The fix to ITS#4556 broke this test: modifying objectClass was forbidden

for anyone, and since LDAP additions now check for attribute write access,
the addition now fails.

Allowing objectClass write access for the user that performs the LDAP
addtition fixes the problem.

Approved by ando@
This commit is contained in:
Emmanuel Dreyfus 2008-10-04 10:12:11 +00:00
parent 8317cdad12
commit 7f085e8b8b

View file

@ -55,6 +55,7 @@ rootpw secret
#access to attrs=objectclass dn.subtree="dc=example,dc=com"
access to attrs=objectclass
by dn.exact="cn=Bjorn Jensen,ou=Information Technology Division,ou=People,dc=example,dc=com" add
by * =rsc stop
#access to filter="(objectclass=person)" attrs=userpassword dn.subtree="dc=example,dc=com"