Thanks for your replies, I will mix both mails here to answer to your
comments:

Olivier:
> You probably do not need a MetaDirectory but you need a StackingDirectory to 
> be able to translate primary keys (DN <-> group id)

I can get group_id from the meta directory mapping cn<->group. But it
have a problem: I can't use local_role interface to asign local roles to
a group. If I use a Stacking Directory (updated doc about directories
will be great!) I can asign local roles to a group, but I can't see
groups info in Directories search (but this is a minor problem, so I
prefer the stack directory)

Georges:
> which objectClass do you use for groups, is it groupOfNames ?
> what's your plan for roles wrt to LDAP schemas ? 

objectClass for groups is groupOfUniqueNames. For the roles I wil try
same approach (I have something done), but if you have something in mind
I will be happy to listen your ideas. Roles objectClass is also
groupOfUniqueName.

> Needless to say, if you've come to a satisfactory setup, we'd be more than 
> happy to integrate it in CPSLDAPSetup. 

If is there a easy way of exporting my setup I have no problem to send it.

I don't understand very well the part of the read_process_exp-based
part. Is there a way to execute a script from the schema? I say
something like doing a search in LDAP to get user groups. Is this posible?



Georges Racinet wrote:
> 
> Le 10 mai 2006, à 18:27, Olivier Grisel a écrit :
> 
>> Georges Racinet a écrit :
>>
>>> The methods doing this synthesis are defined and registered here:
>>> https://svn.nuxeo.org/pub/CPSDirectory/trunk/FieldNamespace.py
>>> About a pure write expression solution, I don't remember much of what
>>> we said about it, Olivier, was there more to it than just avoiding
>>> the search on read-proccess fields ?
>>
>>
>> If we you crossSetList in both schemas (members and groups) as a
>> write_process_expr, one should take care of not triggering infinite
>> loops.
> 
> 
> Yep that's right. IMHO, the current system isn't so bad. It's tolerable
> not being able to search members by the groups they belong to.
> 
> _______________________________________________
> cps-devel mailing list
> http://lists.nuxeo.com/mailman/listinfo/cps-devel
> 

-- 
Aitzol Naberan Burgaña
CodeSyntax
http://www.codesyntax.com
943 82 17 80

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
cps-devel mailing list
http://lists.nuxeo.com/mailman/listinfo/cps-devel

Reply via email to