• Recent
  • Unsolved
  • Tags
  • Popular
  • Users
  • Groups
  • Search
  • Register
  • Login
  • Recent
  • Unsolved
  • Tags
  • Popular
  • Users
  • Groups
  • Search
  • Register
  • Login

LDAP with Access Control, default role assignment at first login

Scheduled Pinned Locked Moved Solved
General Problems
2
3
291
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    symrex
    last edited by Jul 25, 2020, 2:58 PM

    Hello,
    I’m using LDAP with Access Control. LDAP -> User Filter = 991
    I can see all LDAP users in the list and can assign them to the right role.
    Problem:
    When new users logging in for the first time, they have admin status. (undefined role)

    Is there a way to initially assign them to a “guest” role? And promote them by hand afterwards?

    1 Reply Last reply Reply Quote 0
    • T
      Tom Elliott
      last edited by Aug 11, 2020, 7:58 PM

      I’ve seen this request but not quite sure how to move forward.

      Please understand, Access controls, with this iteration of FOG Server, are coded after the fact.

      What do I mean by this?

      FOG didn’t really have any real security controls in place. You, indeed, needed to be logged in to do actions of course, but there weren’t any utilities in place for “modifying” access.

      For a period of time, there was a thing called “mobile” user which basically just allowed a user to use a mobile interface. This interface was coded along side the FOG system, and was a cumbersome tool to maintain. So when we moved to a responsive design, I removed that “mobile” gui as the new GUI is also mobile accessible.

      The Access control plugin is a huge leap toward getting a tool available to limit access based on rules/roles etc…, but it’s not a perfect system as it relies on the User existing in the database first.

      I’m sure we could work to add a utility to enable a “default” role association but right now it doesn’t exist.

      Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG! Get in contact with me (chat bubble in the top right corner) if you want to join in.

      Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

      Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

      1 Reply Last reply Reply Quote 2
      • S
        symrex
        last edited by Jul 28, 2020, 3:13 PM

        PUSH

        I’ve could adjust LDAP login, and allow only admins, but I’ve some students who would also like to work with it.
        So I’m allowing admins (admin role) and students (mobile role) to access.
        But not all students should have full access.

        As I listened, there is a new idea with the new version 1.6 on this subject.
        Hopefully this will solve my problem.

        1 Reply Last reply Reply Quote 0
        • T
          Tom Elliott
          last edited by Aug 11, 2020, 7:58 PM

          I’ve seen this request but not quite sure how to move forward.

          Please understand, Access controls, with this iteration of FOG Server, are coded after the fact.

          What do I mean by this?

          FOG didn’t really have any real security controls in place. You, indeed, needed to be logged in to do actions of course, but there weren’t any utilities in place for “modifying” access.

          For a period of time, there was a thing called “mobile” user which basically just allowed a user to use a mobile interface. This interface was coded along side the FOG system, and was a cumbersome tool to maintain. So when we moved to a responsive design, I removed that “mobile” gui as the new GUI is also mobile accessible.

          The Access control plugin is a huge leap toward getting a tool available to limit access based on rules/roles etc…, but it’s not a perfect system as it relies on the User existing in the database first.

          I’m sure we could work to add a utility to enable a “default” role association but right now it doesn’t exist.

          Please help us build the FOG community with everyone involved. It's not just about coding - way more we need people to test things, update documentation and most importantly work on uniting the community of people enjoying and working on FOG! Get in contact with me (chat bubble in the top right corner) if you want to join in.

          Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

          Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

          1 Reply Last reply Reply Quote 2
          • 1 / 1
          • First post
            Last post

          232

          Online

          12.0k

          Users

          17.3k

          Topics

          155.2k

          Posts
          Copyright © 2012-2024 FOG Project