On 27.2.2013 17:46, Petr Viktorin wrote:
On 02/27/2013 04:00 PM, Jan Cholasta wrote:
Patch 165:

I have noticed two things that are not really related to your work, but
here they are nonetheless:

+        if self.admin_conn.get_entries(
+                DN(api.env.container_ranges, self.suffix),
+                ldap.SCOPE_ONELEVEL,
+                "objectclass=ipaDomainIDRange"):

Is that a valid filter?

I don't think it is, fixed.

+        if self.admin_conn.get_entries("cn=accounts," + self.suffix,
+                                       ldap.SCOPE_SUBTREE, id_filter):

This doesn't seem right as well, why is the DN class not used here?

I made it a DN.

Patch 167:

-                conn.sasl_interactive_bind_s(None, sasl_auth)
+                conn.do_sasl_gssapi_bind()

sasl_auth is unused after this change, can you please remove it as well
(and cb_info too)?

Removed.

-            self.sasl_interactive_bind_s, timeout, None, SASL_AUTH)
+            self.conn.sasl_interactive_bind_s, timeout, None, SASL_AUTH)

Again, this is not related to your work, but can we please rename
SASL_AUTH to SASL_GSSAPI?

OK, makes sense

Patch 173:

-        res = con.search_st(str(base),
-                            ldap.SCOPE_SUBTREE,
-                            filterstr=srcfilter,
-                            attrlist=attrs,
-                            timeout=10)
+        res = con.get_entries(base, con.SCOPE_SUBTREE, srcfilter, attrs)

I assume the timeout is there for a reason, can you please keep it?

Fixed, thanks

Patch 174:

-                    conn.modify_s(
-                        def_dn,
-                        [(ldap.MOD_REPLACE,
-                        'originfilter',
-                        disable_attr)]
-                    )
+                    entry['originfilter'] = [disable_attr]

I think you forgot to call update_entry here.

Fixed, thanks again.



Thanks. ACK.

--
Jan Cholasta

_______________________________________________
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel

Reply via email to