Don't require a groupOfNames objectClass, other objectClasses (e.g. group) are available and may even be more popular in the Real World (or at least that part of it which installs Microsoft Active Directory 2012 Server Enterprise Edition™®).
This commit is contained in:
parent
6670ffe8d3
commit
cb72ea619e
|
|
@ -119,8 +119,7 @@ evaluate({exists, DNPattern}, Args, _User, LDAP) ->
|
|||
object_exists(DNPattern, Filter, Args, LDAP);
|
||||
|
||||
evaluate({in_group, DNPattern}, Args, #user{impl = UserDN}, LDAP) ->
|
||||
Filter = eldap:'and'([eldap:equalityMatch("objectClass", "groupOfNames"),
|
||||
eldap:equalityMatch("member", UserDN)]),
|
||||
Filter = eldap:equalityMatch("member", UserDN),
|
||||
object_exists(DNPattern, Filter, Args, LDAP);
|
||||
|
||||
evaluate({match, StringQuery, REQuery}, Args, User, LDAP) ->
|
||||
|
|
|
|||
Loading…
Reference in New Issue