MI-DROZ commented on issue #11472:
URL: https://github.com/apache/cloudstack/issues/11472#issuecomment-3210772857

   
   
   > [@DaanHoogland](https://github.com/DaanHoogland), similar issue on 
Discussion
   > 
   > [#10380](https://github.com/apache/cloudstack/discussions/10380)
   
   With this info it seems we should realize accountType is a legacy 
designation needed for backwards compatibility and became a bit redundant when 
dynamic roles were introduced. I have suggested a possible override mechanism 
in [10380](https://github.com/apache/cloudstack/discussions/10380) that may 
make roleid relevant when the account mapping occurs. In our particular 
situation linkAccountToLdap is not useful since we don't want users to see 
other users instances.  See 
https://docs.cloudstack.apache.org/en/latest/adminguide/accounts.html   I 
wonder if you are in the same situation.
   
   Even in the documentation they state: "Most installations need not surface 
the notion of Users; they just have one User per Account."
   This makes the linkDomainToLdap feature more important when one is using the 
autoimport method for user creation.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscr...@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org

Reply via email to