[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

RE: Limiting access to a particular repository subdirectory

From: Srilakshmanan, Lakshman <lakshman.srilakshmanan_at_police.vic.gov.au>
Date: Tue, 13 Oct 2009 15:17:21 +1100

Hi Craig,

The only other method I can think of is to use a pre-commit hook.

Hope this helps.

Thanks
Lakshman
-----Original Message-----
From: Andrey Repin [mailto:anrdaemon_at_freemail.ru]
Sent: Tuesday, 13 October 2009 1:12 PM
To: Craig Pendleton; users_at_subversion.tigris.org
Subject: Re: Limiting access to a particular repository subdirectory

Greetings, Craig Pendleton!

>>> We are currently running Subversion 1.4 through Apache 2.2,
authenticating
>>> our users via LDAP and a ?Require valid-user? parameter. This has
been
>>> working fine for us. We are bringing in a third party who will
only be
>>> working several levels deep in the repository and would like to
restrict
>>> their access to these subdirectories only. We would like to use
LDAP
>>> groups to accomplish this. Basically what we are looking for is
the
>>> following:
>>>
>>> /repository/foo (read, write by A, B LDAP groups; no read or
write for C
>>> group )
>>> /repository/foo/bar (read, write by A, B, C LDAP groups)
>>>
>>> I?ve tried multiple <Location> directives (with different ?Require
>>> ldap-filter? parameters) into different parts of the same
>>> repository, with no success. ?Require ldap-group? will not work for

>>> us as it seems to only accept one group as argument.
>>>
>>> Is this possible? If so, can someone point me in the right
direction?
>>> Thank you in advance.

>> Have you considered Path-Based Authorization
>>
>> http://svnbook.red-bean.com/en/1.4/svn.serverconfig.pathbasedauthz.ht
>> ml

> Hi Lakshman,

> Thank you for the suggestion and the quick reply. Path-based
authorization
> would be ideal, but my understanding is that this requires a flat file

> containing path, user and/or group details and cannot query group
membership
> from LDAP. Can path-based authorization leverage LDAP groups? I
didn?t
> find any documentation indicating that it can, so I?m looking for
> alternatives.

> Suggestions greatly appreciated.

I suggest you upgrade your ancient server software and read appropriate
documentation.
http://svnbook.red-bean.com/nightly/en/svn-book.html#svn.serverconfig.pa
thbasedauthz

(Same for 1.5
http://svnbook.red-bean.com/en/1.5/svn-book.html#svn.serverconfig.pathba
sedauthz
)

--
WBR,
 Andrey Repin (anrdaemon_at_freemail.ru) 13.10.2009, <6:07>
Sorry for my terrible english...
------------------------------------------------------
http://subversion.tigris.org/ds/viewMessage.do?dsForumId=1065&dsMessageI
d=2406889
To unsubscribe from this discussion, e-mail:
[users-unsubscribe_at_subversion.tigris.org].
================================================================================================
EMAIL DISCLAIMER
This email and any attachments are confidential. They may also be subject to copyright.
If you are not an intended recipient of this email please immediately contact us by replying
to this email and then delete this email. 
You must not read, use, copy, retain, forward or disclose this email or any attachment.
We do not accept any liability arising from or in connection with unauthorised use or disclosure 
of the information contained in this email or any attachment.
We make reasonable efforts to protect against computer viruses but we do not accept liability
for any liability, loss or damage caused by any computer virus contained in this email.
================================================================================================
------------------------------------------------------
http://subversion.tigris.org/ds/viewMessage.do?dsForumId=1065&dsMessageId=2406927
To unsubscribe from this discussion, e-mail: [users-unsubscribe_at_subversion.tigris.org].
Received on 2009-10-13 23:48:01 CEST

This is an archived mail posted to the Subversion Users mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.