Uploaded image for project: 'LDAP'
  1. LDAP
  2. LDAP-26

clarify the authentication mechanism

    Details

    • Type: Improvement
    • Status: Open
    • Priority: Major
    • Resolution: Unresolved
    • Affects Version/s: 8.3
    • Fix Version/s: None
    • Component/s: Application, Authenticator
    • Labels:
      None
    • Similar issues:

      Description

      In the specific use case http://extensions.xwiki.org/xwiki/bin/view/Extension/LDAP/Authenticator/UseCases/#HI27minamultiwikienvironmentandIwantmyLDAPuserstoregisteronlyonthemainwiki

      And when LDAP is enabled in the main wiki, and disabled on the child wiki.

      I think it could be great to add the following somewhere as a tooltip in the LDAP App. Or in xwiki.cfg maybe :

      When the LDAP authenticator fails to authenticate to a wiki it will try in the main wiki.

      on the top of that, the above only concerns LDAP users. For master wiki local users to authenticate (ie, not LDAP users) through a child wiki, "trylocal" should be set to "yes" on the child wiki, even if "trylocal" is set to "yes" on the master wiki.

      Where we could think it is enough to have trylocal set to "yes" on the master wiki. We could add "...a login attempt which match a local main user credential isn't in the scope of the LDAP fallback ; trylocal should be set - per wiki - for that purpose". Or something equivalent.

      Hope it is clear enough.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              mh Martin
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated: