yes, it depends mailing how much users yours groups contains since they are resolved and cached on XWiki side so that can be a bit long for very big groups the first time. It's not first log on of each users, the cache is kept for all users it's just the first time an authentication is done (and then when the cache is outdated, see xwiki.authentication.ldap.groupcache_expiration). On Fri, Mar 14, 2014 at 4:04 PM, Pascal BASTIEN <[email protected]> wrote:
Yes thanks you. I already use maping ldap group in my xwiki.cfg. It was working but performence is lower (first log on is long)
________________________________ De : Thomas Mortagne <[email protected]> À : Pascal BASTIEN <[email protected]> Cc : XWiki Users <[email protected]> Envoyé le : Vendredi 14 mars 2014 15h48
Objet : Re: [xwiki-users] Some question about ACL
Depends how advanced you need it to be but you can map LDAP "groups" (it's actually more than what is generally called groups in LDAP world) and you a few related documentation on http://platform.xwiki.org/xwiki/bin/view/AdminGuide/LDAPAuthenticationUseCas... and above xwiki.authentication.ldap.group_mapping property in xwiki.cfg itself.
On Fri, Mar 14, 2014 at 2:43 PM, Pascal BASTIEN <[email protected]> wrote:
K Thanks you.
I think I can use xwiki.users.initialGroups property for my ldap user because the first time my ldap user log on my new xwiki, a new user associate is created.
Anyway, actually I'm testing ACL with some different user case like: someone are in 2 differents groups and must access at space protected by differents access rights with this 2 groups... Have you a advanced documentation about this?
-- Thomas Mortagne