[Date Prev][Date Next]
Patch: ACL #access-id#<invalid-DN> granted access to everyone (ITS#2006)
Full_Name: Hallvard B. Furuseth
Submission from: (NULL) (22.214.171.124)
There is a bug in OpenLDAPaci's "access-id": If the specified DN is
invalid so dnNormalize2() fails, everyone gets access.
This means that e.g. "#access-id#[all]" gives public access, so it
might be considered a feature, but I fixed it anyway:-) I guess that
means the change should be documented in the release notes, though.
See also ITS#2005 (add OpenLDAPaci #public# access).