Skip to content
GitLab
    • Explore Projects Groups Topics Snippets
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • fusiondirectory-plugins fusiondirectory-plugins
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 65
    • Issues 65
    • List
    • Boards
    • Service Desk
    • Milestones
  • Deployments
    • Deployments
    • Releases
  • Packages and registries
    • Packages and registries
    • Container Registry
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • fusiondirectoryfusiondirectory
  • fusiondirectory-pluginsfusiondirectory-plugins
  • Issues
  • #5758
Something went wrong while setting issue due date.
Closed
Open
Issue created 7 years ago by jbecot@jbecotReporter
  • New related issue

  • New related issue

DNS : ACL prevents limited user to delete NS record when removing a system

Closed

DNS : ACL prevents limited user to delete NS record when removing a system

Description

Deleting a system with an admin account remove the DNS entry as well (a blue popup with "DNS update" shows up) while doing it with a limited account does not (no popup and removal is faster).

Meanwhile, renaming a system with the limited account does update the DNS as well (I think it delete/recreate the entries in an LDAP pov). The blue message pops up.

Distribution Name and Version

RHEL7

FusionDirectory Version

1.2 fixes

Plugin with the defect

DNS

PHP version used

5.4

Origin of php packages

epel/rhel channels

Steps to Reproduce

  1. Delete a system
  2. Edit the DNS zone the system was registered in, the record still exists

Expected behavior:

Deletion with limited account

Actual behavior:

No deletion

Reproduces how often: 100%

Additional Information

ACLs : TechDNSZone appplied to zone "example.com." : DNS Zone -> Object: DNS Zone :

  • Create + Delete objects
    • Reverse Zones for this zone rw
    • DNS Records for this zone (dnsRecords) rw DNS Zone -> Object: DNS Record :
  • Create + Delete objects
    • A and PTR Records rw
TechDNSReload applied to system object dns-m (master dns server):
Server -> Server Object : This server name (cn) r / A short description (description) r
Server -> DNS : Full object : r

TechDNSSystems applied to department "Postes utilisateurs" containing systems :
DNS Zone -> Object: DNS Zone:  DNS Records for this zone (dnsRecords) rw 
         -> Object: DNS Records : A Records (dnsRecord_aRecord) rw
Workstation -> Object: Workstation : Create / Move / Delete / rw (full)
            -> Object: Model r
            -> Object: DNS Create / rw (full) + DNS Zone for this host (fdDNSZoneDn) rw
            -> Object DHCP : DHCP Hosts declared for this system (dhcpHosts) rw
Edited 7 years ago

    Tasks

    0
    Cannot read properties of undefined (reading 'workItem')

    Linked items
    0

    Link issues together to show that they're related. Learn more.

    Activity


    • bmortier changed the description 7 years ago

      changed the description

    • bmortier added PJ1706-0097 enhancement plugin-dns labels 7 years ago

      added PJ1706-0097 enhancement plugin-dns labels

    • bmortier assigned to @MCMic 7 years ago

      assigned to @MCMic

    • Côme Chilliet moved to fd#5747 (closed) 7 years ago

      moved to fd#5747 (closed)

    Please register or sign in to reply
    Assignee
    Côme Chilliet's avatar
    Côme Chilliet
    Assign to
    Labels
    0
    None
    0
    None
      Assign labels
    • Manage project labels

    Milestone
    No milestone
    None
    Due date
    None
    None
    None
    Time tracking
    No estimate or time spent
    Confidentiality
    Not confidential
    Not confidential

    You are going to turn on confidentiality. Only project members with at least the Reporter role, the author, and assignees can view or be notified about this issue.

    Lock issue
    Unlocked
    0
    0 Participants
    Reference:

    Menu

    Explore Projects Groups Topics Snippets