mirror of
https://github.com/inverse-inc/sogo.git
synced 2026-10-05 20:10:33 +00:00
fix(core): Add disableSubgroups option in SOGoUserSources LDAP settings to avoid infinite recursive loop when using a group name with the same name as a member. Fixes #5913
This commit is contained in:
@@ -1270,6 +1270,10 @@ Defaults to `YES` when unset.
|
|||||||
|globalAddressBookFirstEntriesCount (optional)
|
|globalAddressBookFirstEntriesCount (optional)
|
||||||
|Number of entries displayed when `listRequiresDot` is enabled. Default value is `-1` (all records). If source is LDAP, the LDAP overlay sssvlv must be enabled on the system for server side sorting.
|
|Number of entries displayed when `listRequiresDot` is enabled. Default value is `-1` (all records). If source is LDAP, the LDAP overlay sssvlv must be enabled on the system for server side sorting.
|
||||||
|
|
||||||
|
|disableSubgroups (optional)
|
||||||
|
|If set to `YES`, disable recursive search. Consider this option when groups have the same name than a member (https://bugs.sogo.nu/view.php?id=5913).
|
||||||
|
Defaults to `NO` when unset.
|
||||||
|
|
||||||
|ModulesConstraints (optional)
|
|ModulesConstraints (optional)
|
||||||
|Limits the access of any module through a constraint based on an LDAP
|
|Limits the access of any module through a constraint based on an LDAP
|
||||||
attribute; must be a dictionary with keys `Mail`, and/or `Calendar`,
|
attribute; must be a dictionary with keys `Mail`, and/or `Calendar`,
|
||||||
|
|||||||
@@ -66,6 +66,8 @@
|
|||||||
BOOL _listRequiresDot;
|
BOOL _listRequiresDot;
|
||||||
int _globalAddressBookFirstEntriesCount;
|
int _globalAddressBookFirstEntriesCount;
|
||||||
|
|
||||||
|
BOOL _disableSubgroups;
|
||||||
|
|
||||||
NSString *_domain;
|
NSString *_domain;
|
||||||
NSString *_contactInfoAttribute;
|
NSString *_contactInfoAttribute;
|
||||||
BOOL _groupExpansionEnabled;
|
BOOL _groupExpansionEnabled;
|
||||||
|
|||||||
@@ -108,6 +108,8 @@ static Class NSStringK;
|
|||||||
_listRequiresDot = YES;
|
_listRequiresDot = YES;
|
||||||
_globalAddressBookFirstEntriesCount = -1;
|
_globalAddressBookFirstEntriesCount = -1;
|
||||||
|
|
||||||
|
_disableSubgroups = NO;
|
||||||
|
|
||||||
_passwordPolicy = NO;
|
_passwordPolicy = NO;
|
||||||
_updateSambaNTLMPasswords = NO;
|
_updateSambaNTLMPasswords = NO;
|
||||||
_lookupFields = [NSArray arrayWithObject: @"*"];
|
_lookupFields = [NSArray arrayWithObject: @"*"];
|
||||||
@@ -171,7 +173,7 @@ static Class NSStringK;
|
|||||||
inDomain: (NSString *) sourceDomain
|
inDomain: (NSString *) sourceDomain
|
||||||
{
|
{
|
||||||
SOGoDomainDefaults *dd;
|
SOGoDomainDefaults *dd;
|
||||||
NSNumber *udQueryLimit, *udQueryTimeout, *udGroupExpansionEnabled, *dotValue;
|
NSNumber *udQueryLimit, *udQueryTimeout, *udGroupExpansionEnabled, *dotValue, *disableSubgroupsValue;
|
||||||
|
|
||||||
if ((self = [self init]))
|
if ((self = [self init]))
|
||||||
{
|
{
|
||||||
@@ -207,6 +209,10 @@ static Class NSStringK;
|
|||||||
[self setGlobalAddressBookFirstEntriesCount: [[udSource objectForKey: @"globalAddressBookFirstEntriesCount"] intValue]];
|
[self setGlobalAddressBookFirstEntriesCount: [[udSource objectForKey: @"globalAddressBookFirstEntriesCount"] intValue]];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
disableSubgroupsValue = [udSource objectForKey: @"disableSubgroups"];
|
||||||
|
if (disableSubgroupsValue)
|
||||||
|
_disableSubgroups = [disableSubgroupsValue boolValue];
|
||||||
|
|
||||||
[self setContactMapping: [udSource objectForKey: @"mapping"]
|
[self setContactMapping: [udSource objectForKey: @"mapping"]
|
||||||
andObjectClasses: [udSource objectForKey: @"objectClasses"]];
|
andObjectClasses: [udSource objectForKey: @"objectClasses"]];
|
||||||
|
|
||||||
@@ -2355,16 +2361,21 @@ _makeLDAPChanges (NGLdapConnection *ldapConnection,
|
|||||||
user = [SOGoUser userWithLogin: login roles: nil];
|
user = [SOGoUser userWithLogin: login roles: nil];
|
||||||
if (user)
|
if (user)
|
||||||
{
|
{
|
||||||
contactInfos = [self lookupContactEntryWithUIDorEmail: login inDomain: nil];
|
if (!_disableSubgroups) {
|
||||||
if ([contactInfos objectForKey: @"isGroup"])
|
contactInfos = [self lookupContactEntryWithUIDorEmail: login inDomain: nil];
|
||||||
|
if ([contactInfos objectForKey: @"isGroup"])
|
||||||
{
|
{
|
||||||
subusers = [self membersForGroupWithUID: login];
|
subusers = [self membersForGroupWithUID: login];
|
||||||
[members addObjectsFromArray: subusers];
|
[members addObjectsFromArray: subusers];
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
[members addObject: user];
|
[members addObject: user];
|
||||||
}
|
}
|
||||||
|
} else {
|
||||||
|
[members addObject: user];
|
||||||
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
[pool release];
|
[pool release];
|
||||||
}
|
}
|
||||||
@@ -2377,16 +2388,20 @@ _makeLDAPChanges (NGLdapConnection *ldapConnection,
|
|||||||
user = [SOGoUser userWithLogin: login roles: nil];
|
user = [SOGoUser userWithLogin: login roles: nil];
|
||||||
if (user)
|
if (user)
|
||||||
{
|
{
|
||||||
contactInfos = [self lookupContactEntryWithUIDorEmail: login inDomain: nil];
|
if (!_disableSubgroups) {
|
||||||
if ([contactInfos objectForKey: @"isGroup"])
|
contactInfos = [self lookupContactEntryWithUIDorEmail: login inDomain: nil];
|
||||||
|
if ([contactInfos objectForKey: @"isGroup"])
|
||||||
{
|
{
|
||||||
subusers = [self membersForGroupWithUID: login];
|
subusers = [self membersForGroupWithUID: login];
|
||||||
[members addObjectsFromArray: subusers];
|
[members addObjectsFromArray: subusers];
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
[members addObject: user];
|
[members addObject: user];
|
||||||
}
|
}
|
||||||
|
} else {
|
||||||
|
[members addObject: user];
|
||||||
|
}
|
||||||
}
|
}
|
||||||
[pool release];
|
[pool release];
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user