Thomas Bruederli
a976842f03
Allow to limit user search (from new folder navigation) in multi-domain setups:
...
Provide the 'kolab_users_directory' config option with placeholders %dc, %d, %u,
%fu or %dn in base_dn or filter properties.
2014-11-17 14:33:04 +01:00
Thomas Bruederli
e618f0093c
Support wildcard option to allow full access
2014-10-11 03:28:17 +02:00
Thomas Bruederli
1e0b0cdf9d
Check effective rights for the login-as feature to improve the delegation model
...
and allow controlling the administration privileges in LDAP (#1834 ).
This deprecates the config options 'kolab_auth_group', 'kolab_auth_role_value'
and 'kolab_auth_allowed_tasks'.
Admin privileges (per Roundcube task) and the required effective rights
are now defined in 'kolab_auth_admin_rights'.
2014-10-11 03:14:45 +02:00
Aleksander Machniak
fbaa3f865e
Add option to define list of tasks to which an admin has access ( #3444 )
...
E.g. allow admins (using "Login as" feature) to see only user settings.
2014-08-25 14:27:23 -04:00
Aleksander Machniak
a355288360
Fix so role-based plugins are loaded not required
2014-07-11 10:37:17 +02:00
Aleksander Machniak
26767a1669
Enable audit debugging only when logged as another user (Bug #3109 ),
...
fix default of kolab_auth_auditlog in sample config file
2014-06-02 14:02:31 +02:00
Aleksander Machniak
9a2a7e48a1
Fix SMTP authentication when using "Login As" feature
2014-03-13 10:29:47 +01:00
Aleksander Machniak
71c66461d5
Load per-user settings/plugins also just after log in
2014-02-20 15:41:12 +01:00
Aleksander Machniak
d7a607e1b1
Fix missing resolving of %dn in kolab_auth_role_settings
2014-01-24 13:44:04 +01:00
Thomas Bruederli
8996e8fa60
Adapt write_log hook to new per-user logging capabilities of Roundcube core ( #2750 ):
...
- Return the 'dir' property in write_log hook instead of writing the log directly
- Provide a user log directory during authentication with the username submitted or retrieved from LDAP respectively
- Requires Roundcube core rev 3786a4
2014-01-16 10:04:03 +01:00
Thomas Bruederli
5bbbcca49c
Report LDAP server error in plugin hook return data ( #2727 )
2014-01-07 15:31:48 +01:00
root
ab9c3db43a
Improved role-based settings handling, especially 'skin' setting
2013-12-06 14:11:05 +01:00
Aleksander Machniak
004cd5ac56
Fixed kolab_auth_mailhost feature
2013-10-08 13:45:23 +02:00
Aleksander Machniak
d5af672f6b
Fix sql debugging in audit mode
2013-10-07 12:38:36 +02:00
Aleksander Machniak
0cbce32636
Fixed kolab_auth_auditlog feature
2013-10-07 10:59:25 +02:00
Jeroen van Meeuwen (Kolab Systems)
c97615aeef
Log failed logins (always)
2013-10-04 13:00:27 +02:00
Aleksander Machniak
a3ef9150a4
Update copyright year
2013-10-04 12:03:04 +02:00
Aleksander Machniak
1f3f8e69db
Support multi-domain configuration of LDAP addressbooks (Bug #2292 )
2013-10-04 11:54:49 +02:00
Aleksander Machniak
657093d838
Use password_ldap_bind hook to provide LDAP user DN for password change. (Request #2217 )
...
Requires ldap_simple driver to be enabled in password plugin config.
2013-09-27 13:14:29 +02:00
Aleksander Machniak
6556c1a1d4
Improved performance of load_user_role_plugins_and_settings(), we cache
...
some data in session so we can skip LDAP connection + bind + search
on every request (Bug #2241 )
2013-09-19 11:46:19 +02:00
Jeroen van Meeuwen (Kolab Systems)
610036138a
Add the possibility to set the a mailhost attribute value to be used as the IMAP server address to connect to.
2013-09-11 16:33:07 +01:00
Aleksander Machniak
8002f2b0ca
Take identities_level setting into consideration when identity form is going to be modified
2013-09-11 14:07:50 +02:00
Aleksander Machniak
cdd23787e2
Fix so kolab_delegation plugin can modify list of addresses in
...
identity form (Bug #2191 )
2013-09-11 14:01:38 +02:00
Thomas Bruederli
74f1d3ba85
Hook into identities form and present a list of allowed sender email addresses ( #2191 )
2013-09-05 10:13:21 +02:00
Jeroen van Meeuwen (Kolab Systems)
44021155b0
Make sure we loop over non-empty arrays only
2013-08-19 13:54:08 +02:00
Jeroen van Meeuwen (Kolab Systems)
af0383d2d2
Correct typo (thanks to Daniel Morlock)
2013-08-05 15:37:23 +01:00
Jeroen van Meeuwen (Kolab Systems)
a6ee501a68
There's no need to get the user record
2013-08-05 11:18:29 +01:00
Jeroen van Meeuwen (Kolab Systems)
3d96d74298
Use $ldap->parse_vars to allow role specific settings and plugins to be applied to multi-domain environments through the expansion of '%dc'
2013-08-05 11:15:01 +01:00
Aleksander Machniak
e69e9b90ae
Make kolab_auth's LDAP class be based on new rcube_ldap_generic class.
...
Move kolab_auth_ldap into separate file.
Some improvements, including performance improvement in kolab_delegate
2013-06-25 12:27:26 +02:00
Aleksander Machniak
27e57c7335
Fix undefined or unused variable errors caught in static code analysis
2013-05-07 12:16:11 +02:00
Thomas Bruederli
d85e012596
Adapt to recent changes in Roundcube core
2013-02-07 19:33:41 +01:00
Aleksander Machniak
035bd6fc3b
Support Organization field in default identity ( #1189 )
2012-12-19 15:20:41 +01:00
Aleksander Machniak
5d7a7fc353
Revert last change, core uses storage_connect hook now
2012-12-13 14:42:37 +01:00
Aleksander Machniak
c666c6a757
Fix hook name: storage_connect -> imap_connect
2012-12-13 14:37:41 +01:00
Aleksander Machniak
82d9fc6fed
Make possible reusage of LDAP object by other plugins
2012-12-04 14:43:36 +01:00
Aleksander Machniak
81fdc1642a
Remove redundant parse_host() call
2012-10-17 13:46:49 +02:00
Aleksander Machniak
6d46e0c9f2
More Roundcube Framework related fixes
2012-10-17 13:43:08 +02:00
Aleksander Machniak
2d08c58e56
Fix/prepare plugins to use out of Roundcube (where rcmail object doesn't exist)
2012-10-17 11:54:25 +02:00
Aleksander Machniak
bde912a1fe
Create identity for each email address of a new user
2012-10-08 11:32:49 +02:00
Aleksander Machniak
a7c06ff2fd
Support array of fields in kolab_auth_name/kolab_auth_email config,
...
use first non-empty value (#1012 ).
Fix lost kolab_auth_email handling.
2012-10-08 10:15:32 +02:00
Aleksander Machniak
ad9a89eece
Throw login error when LDAP connection failes or user not found in LDAP (Bug #512 )
2012-10-08 09:38:16 +02:00
Aleksander Machniak
e0962a3936
CS fixes
2012-10-08 09:22:07 +02:00
Aleksander Machniak
73d1dba092
Remove alias handling - the feature doesn't exist in core anymore
2012-09-23 09:25:06 +02:00
Aleksander Machniak
d1fecda9de
Store user's UID in session for use by other plugins (e.g. owncloud)
...
Small code style fixes
2012-02-29 13:09:43 +01:00
Aleksander Machniak
607fd7b43b
Updates for Roundcube 0.8
2012-01-23 10:16:30 +01:00
Jeroen van Meeuwen (Kolab Systems)
d3d3a6e323
Add kolab_auth capability to use nsroledn attribute values attached to a user's entry (roles for users) to imply loading/setting configuration settings and loading additional plugins
2011-12-04 14:11:07 +00:00
Aleksander Machniak (Kolab Systems)
65abe8a4cb
Added package.xml files, some cleanups
2011-11-21 11:20:48 +01:00
Aleksander Machniak (Kolab Systems)
4a498714dd
Changed license to AGPL
2011-10-27 10:20:46 +02:00
Aleksander Machniak
6a423a38e5
Implemented "Login As" feature with Horde classes support
...
Store admin credentails in session (encrypted) to make things simpler
2011-10-26 09:36:18 +02:00
Jeroen van Meeuwen (Kolab Systems)
a9459ab448
Enhance kolab_auth plugin with the ability to perform audit logging.
...
Setting $rcmail_config['kolab_auth_auditlog'] increases all logging
verbosity to the maximum, and logs the information on the session
to a user + loginas specific directory if capable.
2011-09-20 12:43:57 +01:00