Opened 8 years ago

Last modified 6 months ago

#3036 reopened enhancement

LdapPlugin should follow LDAP aliases

Reported by: r_j_h_box-buy@… Owned by: eblot
Priority: normal Component: LdapPlugin
Severity: minor Keywords:
Cc: Trac Release: 0.10


I'm using an LDAP configuration where I need to place my Trac groups in one part of the tree, as aliases to groups that are defined in other parts of the tree.

In case anybody's wondering, this is to allow me to administer my Trac instances through my Apple OSX Leopard Server's Workgroup Administrator application.

There's a feature built into the LDAP libraries which specifies that lookups should follow aliases, and it appears that this isn't currently enabled. If you can recommend a workaround and/or a code fix on the plugin, that would very much appreciated.

Attachments (1)

deref_searching.patch (537 bytes) - added by ektich@… 6 months ago.
enable alias dereference during search operatoins

Download all attachments as: .zip

Change History (5)

comment:1 Changed 8 years ago by anonymous



    Controls whether aliases are automatically dereferenced. This must be one of DEREF_NEVER, DEREF_SEARCHING, DEREF_FINDING, or DEREF_ALWAYS. This option is mapped to option constant OPT_DEREF and used in the underlying OpenLDAP lib.

comment:2 Changed 8 years ago by anonymous

  • Resolution set to fixed
  • Status changed from new to closed

comment:3 Changed 8 years ago by anonymous

  • Resolution fixed deleted
  • Status changed from closed to reopened

Changed 6 months ago by ektich@…

enable alias dereference during search operatoins

comment:4 Changed 6 months ago by ektich@…

I've added a simple patch that enables alias dereferencing during search operations. It works for me with OpenLDAP version 2.4.11 and the alias record described by the following LDIF:

dn: cn=tracgroup,ou=people,dc=example,dc=com
objectClass: alias
objectClass: extensibleObject
cn: tracgroup
aliasedObjectName: cn=tracgroup,ou=groups,dc=example,dc=com

My main need for this feature is an inability of LdapAuthStorePlugin to keep users and groups on different branches of the LDAP tree.

Add Comment

Modify Ticket

as reopened The owner will remain eblot.

E-mail address and user name can be saved in the Preferences.

Note: See TracTickets for help on using tickets.