[Date Prev][Date Next]
Re: Move SLAPI in an overlay...
>> That allows global overlays to implement ACL checking.
>but this is not working, because the BackendDB data loses information
>about the rootdn, the per-backend ACLs and so (for instance, test002 is no
>longer working...). I'll back out acl.c:1.280 until we find a better
Bummer. One solution might be to have a fe_access_allowed() that selects
the appropriate backend:
struct berval *val,
slap_mask_t *maskp )
be_orig = op->o_bd;
/* XXX is op->o_req_ndn always appropriate? */
op->o_bd = select_backend( &op->o_req_ndn, 0, 0 );
rc = slap_access_allowed( op, e, desc, val, access, state, maskp );
op->o_bd = be_orig;
But, can we rely on op->o_req_ndn being the DN that was used to select
the original backend? Not, say, for entry adds, I would have thought.
Any other ideas?