Re: does back-sql bypass ACL ?

Frederic Saincy writes:

# this DOES NOT WORK # (even anonymous can add/delete entries, modify attributes... )
access to *
by dn="cn=root,=sql,c=RU" write
by * read

At a first glance, yes: there's no ACL check for write operations.
I guess back-sql is intended to allow --wiewing-- of sql data more
than modifying it. I think you should disallow modifications by
means of SQL permissions on the tables back-sql is using.


