[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: Limiting access to a particular repository subdirectory

From: Craig Pendleton <craig.pendleton_at_healthlanguage.com>
Date: Tue, 13 Oct 2009 10:55:09 -0600


Thank you the suggestions on this issue. For those with a similar setup,
we ended up using path-based authorization in conjunction with Jeremy
Whitlock's LDAP Authz script (http://www.thoughtspark.org/node/26), which is
working perfectly.


On 10/12/09 10:17 PM, "Srilakshmanan, Lakshman"
<lakshman.srilakshmanan_at_police.vic.gov.au> wrote:

> Hi Craig,
> The only other method I can think of is to use a pre-commit hook.
> Hope this helps.
> Thanks
> Lakshman
> -----Original Message-----
> From: Andrey Repin [mailto:anrdaemon_at_freemail.ru]
> Sent: Tuesday, 13 October 2009 1:12 PM
> To: Craig Pendleton; users_at_subversion.tigris.org
> Subject: Re: Limiting access to a particular repository subdirectory
> Greetings, Craig Pendleton!
>>>> We are currently running Subversion 1.4 through Apache 2.2,
> authenticating
>>>> our users via LDAP and a ?Require valid-user? parameter. This has
> been
>>>> working fine for us. We are bringing in a third party who will
> only be
>>>> working several levels deep in the repository and would like to
> restrict
>>>> their access to these subdirectories only. We would like to use
>>>> groups to accomplish this. Basically what we are looking for is
> the
>>>> following:
>>>> /repository/foo (read, write by A, B LDAP groups; no read or
> write for C
>>>> group )
>>>> /repository/foo/bar (read, write by A, B, C LDAP groups)
>>>> I?ve tried multiple <Location> directives (with different ?Require
>>>> ldap-filter? parameters) into different parts of the same
>>>> repository, with no success. ?Require ldap-group? will not work for
>>>> us as it seems to only accept one group as argument.
>>>> Is this possible? If so, can someone point me in the right
> direction?
>>>> Thank you in advance.
>>> Have you considered Path-Based Authorization
>>> http://svnbook.red-bean.com/en/1.4/svn.serverconfig.pathbasedauthz.ht
>>> ml
>> Hi Lakshman,
>> Thank you for the suggestion and the quick reply. Path-based
> authorization
>> would be ideal, but my understanding is that this requires a flat file
>> containing path, user and/or group details and cannot query group
> membership
>> from LDAP. Can path-based authorization leverage LDAP groups? I
> didn?t
>> find any documentation indicating that it can, so I?m looking for
>> alternatives.
>> Suggestions greatly appreciated.

This message, as well as any attached document, contains information from Health Language, Inc. that is confidential.  The information is intended only for the use of the addressee named above.  If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution or the taking of any action in reliance on the contents of this message or its attachments is strictly prohibited, and may be unlawful.  If you have received this message in error, please delete all electronic copies of this message and its attachments, if any, destroy any hard copies you may have created, without disclosing the contents, and notify the sender immediately.  Unless expressly stated otherwise, nothing contained in this message should be construed as a digital or electronic signature, nor is it intended to reflect an intention to make an agreement by electronic means.
To unsubscribe from this discussion, e-mail: [users-unsubscribe_at_subversion.tigris.org].
Received on 2009-10-13 23:47:59 CEST

This is an archived mail posted to the Subversion Users mailing list.