Vincent, Sergiu, and the whole community: My conversation begun by Gunther Leeb has continued offline and I've agreed to help him implement a solution similar to one I've created, which will probably be generally useful. Ironically enough, we seem to have validated the old adage of the cobbler's children going barefoot - we're working on a feature of a Wiki, and though we have a community of interested users and developers and access to a Wiki, we began by still using a one-to-one email exchange. In repentance thereof, I wish to nail down a page or three on xwiki.org to simultaneously develop, publish, and offer for comment the work we are doing. Where would be the best place to put this? The topic is enhancing the LDAP authentication service implementation in the ways that Gunter needs, which would add a feature to discriminate on values in the LDAP-supplied user information. brain[sic]
Hi Brian, On Mar 27, 2007, at 3:59 PM, THOMAS, BRIAN M ((ATTSI)) wrote:
Vincent, Sergiu, and the whole community:
My conversation begun by Gunther Leeb has continued offline and I've agreed to help him implement a solution similar to one I've created, which will probably be generally useful.
Ironically enough, we seem to have validated the old adage of the cobbler's children going barefoot - we're working on a feature of a Wiki, and though we have a community of interested users and developers and access to a Wiki, we began by still using a one-to-one email exchange.
In repentance thereof, I wish to nail down a page or three on xwiki.org to simultaneously develop, publish, and offer for comment the work we are doing.
Where would be the best place to put this? The topic is enhancing the LDAP authentication service implementation in the ways that Gunter needs, which would add a feature to discriminate on values in the LDAP-supplied user information.
We have a place on xwiki.org to discuss community ideas before moving them to pages proper. It's in http://www.xwiki.org/xwiki/bin/view/Idea/ Feel free to use it! Thanks for asking :) -Vincent
THOMAS, BRIAN M (ATTSI) wrote:
Vincent, Sergiu, and the whole community:
My conversation begun by Gunther Leeb has continued offline and I've agreed to help him implement a solution similar to one I've created, which will probably be generally useful.
Hey, I am also going through LDAP interface. My problem is slightly different, I want to use name other than ActiveDirectory username as WikiName. I am not sure how does that help you, but if I can assist you in some way please let me know.
Eeek. After ribbing Gunter for mixing up my name, I misspelled his. Your pardon, Gunter; I knew better! I've started the discussion in http://www.xwiki.org/xwiki/bin/view/Idea/FilteringLDAPauthenticatedUsers . brain[sic]
-----Original Message----- From: news [mailto:[email protected]] On Behalf Of Zeljko Trogrlic Sent: Tuesday, March 27, 2007 2:39 PM To: [email protected] Subject: [xwiki-users] Re: Scratchpad for howto on xwiki.org
THOMAS, BRIAN M (ATTSI) wrote:
Vincent, Sergiu, and the whole community:
My conversation begun by Gunther Leeb has continued offline and I've agreed to help him implement a solution similar to one I've created, which will probably be generally useful.
Hey, I am also going through LDAP interface. My problem is slightly different, I want to use name other than ActiveDirectory username as WikiName. I am not sure how does that help you, but if I can assist you in some way please let me know.
When we touch that component, I like to hear your requirements. Maybe they are easy to implement in one step all togther. And - of course - I can always use help, testing and tips :) No guarantee yet that I/we get the time and experience with XWiki to get any of the desired features done. (Caveat: I don't have an AD available for testing) Please add your ideas to that XWiki page. BTW: I plan to post a summary of the result to the list as soon as we have something more concret. Gunter
Zeljko Trogrlic <[email protected]> 27.03.2007 21:39 >>> THOMAS, BRIAN M (ATTSI) wrote: Vincent, Sergiu, and the whole community:
My conversation begun by Gunther Leeb has continued offline and I've agreed to help him implement a solution similar to one I've created, which will probably be generally useful.
Hey, I am also going through LDAP interface. My problem is slightly different, I want to use name other than ActiveDirectory username as WikiName. I am not sure how does that help you, but if I can assist you in some way please let me know. ------------------------------------------------------------------------------- Diese E-Mail enthaelt vertrauliche und/oder rechtlich geschuetzte Informationen. Wenn Sie nicht der richtige Adressat sind oder diese E-Mail irrtuemlich erhalten haben, informieren Sie bitte sofort den Absender und vernichten Sie diese Mail. Das unerlaubte Kopieren sowie die unbefugte Weitergabe dieser Mail ist nicht gestattet. The information transmitted is intended only for the person or entity to which it is addressed and may contain confidential and/or privileged material. Any review, retransmission, dissemination or other use of, or taking of any action in reliance upon, this information by persons or entities other than the intended recipient is prohibited. If you received this in error, please contact the sender and delete the material from any computer. -------------------------------------------------------------------------------
When we touch that component, I like to hear your requirements. Maybe they are easy to implement in one step all togther. And - of course - I can always use help, testing and tips :) No guarantee yet that I/we get the time and experience with XWiki to get any of the desired features done. (Caveat: I don't have an AD available for testing)
I've stated my understanding of Zeljko's requirement on the named wiki page http://www.xwiki.org/xwiki/bin/view/Idea/FilteringLDAPauthenticatedUsers . It's only the rudest beginning, since I had to leave for the day but I wanted something there to have an address to which to point and a seed of the idea. And Gunter, I'm sure that, with Microsoft's rigorous adherence to standards, you needn't worry about whether Active Directory will behave appropriately just as any LDAP implementation would. (I don't really need to tag the above sentence with something cute and geeky like <irony mood="bitter"> or an equivalent emoticon there, do I? Like most of my sort, I deplore stating the obvious, forgetting that one man's 'obvious' is another's 'inscrutable'...)
Please add your ideas to that XWiki page.
But of course...!
BTW: I plan to post a summary of the result to the list as soon as we have something more concret.
And perhaps a JIRA entry, if it looks like an enhancement that can be generally useful without unnecessarily complicating the lives of those who don't need it... brain[sic] PS Zeljko: In Hungary you do put given name first, correct? and socially it is proper to address or refer to someone by his given name? I'd love to see a phonetic spelling of your name, which to an Anglophone contains three consecutive consonants, though I know that 'j', descended as it is from the Greek iota, is effectively a vowel in some Eastern European languages... On the bright side, there's no chance of absent-mindedly typing a more familiar (to me) spelling as I did to Gunter.
THOMAS, BRIAN M (ATTSI) wrote:
PS Zeljko: In Hungary you do put given name first, correct? and socially it is proper to address or refer to someone by his given name? I'd love to see a phonetic spelling of your name, which to an Anglophone contains three consecutive consonants, though I know that 'j', descended as it is from the Greek iota, is effectively a vowel in some Eastern European languages... On the bright side, there's no chance of absent-mindedly typing a more familiar (to me) spelling as I did to Gunter.
In Hungary, given names traditionally come after the family name. I read this in Wikipedia because I'm not from Hungary. :) I'm not far from the border, though: http://en.wikipedia.org/wiki/Osijek#Institutions_and_industries Hungary is straight above. Although domain .hr associate to Hungary, their 2-letter ISO code is "hu". "hr" stands for Croatia, because our local name is Hrvatska. I was surprised when I noticed that GMANE added national flag to my posts. It is common here to write given name first, or to use encyclopedic format: family, given (not so common) I'm not sure how write it phonetically. It is made of 5 letters (first has reversed caret on top): v Z e lj k o Let's try pronunciation: v Z like first letter in "Jet'aime" e like "a" in "fat" lj try to say "l" and "y" at the same time k as in English o like "o" in "top" You can record it and sent it to me to check did I described it correctly.
Hi, What do you mean by discriminating on values in the LDAP supplier information ? Do you mean you want to create "groups" based on LDAP info ? That's indeed interesting. While you are at it, there are a few enhancements that would be interesting in LDAP: - support a cache of the LDAP authentication - handle more regulare updates of the wiki profile based on the LDAP info Ludovic THOMAS, BRIAN M (ATTSI) a écrit :
Vincent, Sergiu, and the whole community:
My conversation begun by Gunther Leeb has continued offline and I've agreed to help him implement a solution similar to one I've created, which will probably be generally useful.
Ironically enough, we seem to have validated the old adage of the cobbler's children going barefoot - we're working on a feature of a Wiki, and though we have a community of interested users and developers and access to a Wiki, we began by still using a one-to-one email exchange.
In repentance thereof, I wish to nail down a page or three on xwiki.org to simultaneously develop, publish, and offer for comment the work we are doing.
Where would be the best place to put this? The topic is enhancing the LDAP authentication service implementation in the ways that Gunter needs, which would add a feature to discriminate on values in the LDAP-supplied user information.
brain[sic]
------------------------------------------------------------------------
-- You receive this message as a subscriber of the [email protected] mailing list. To unsubscribe: mailto:[email protected] For general help: mailto:[email protected]?subject=help ObjectWeb mailing lists service home page: http://www.objectweb.org/wws
-- Ludovic Dubost Blog: http://www.ludovic.org/blog/ XWiki: http://www.xwiki.com Skype: ldubost GTalk: ldubost AIM: nvludo Yahoo: ludovic
What do you mean by discriminating on values in the LDAP supplier information ? Do you mean you want to create "groups" based on LDAP info ? That's indeed interesting.
Gunter's stated requirement (as I understand it) was primarily the ability to refuse entry to users whose LDAP-supplied (not "supplier", in case you misread my note rather than mistyping your question) information didn't meet certain criteria - specifically, in his case, that the DN did not contain an O (Organization) attribute matching one of a list of authorized entities. His need, it turns out, could be satisfied by a simple regular expression, but some may need specific lists of authorized values too irregular to be distinguished by a regex and too numerous or dynamic to allow enumeration in a static list. A requirement that I had in a (somewhat) similar situation (that used a servlet filter instead of re-implementing any of XWiki's access-control services) was that information provided (via encrypted and signed cookies) by the external authentication service should determine membership in pre-established XWiki groups - three organizations had three separate spaces, and XWiki groups were created to be given access to those spaces. Eligibility for embership in the groups was determined by a wiki page containing objects of a class naming the group, a property name identifying a field in the cookie data (in this case the organization code) and a regular expression which, if matched by the named field, would indicate eligibility. Group memberships would then be updated in accordance with the indicated eligibility.
While you are at it, there are a few enhancements that would be interesting in LDAP:
- support a cache of the LDAP authentication - handle more regulare updates of the wiki profile based on the LDAP info
As to these things, I think that the offer you often give to list members applies to you as well, no...? :> It's what I love about wikis, particularly XWiki: I get to tell my users: "Do it yourself!" or with less technical users, I borrow the Home Depot slogan: "You can do it; we can help!" In all seriousness, of course: Thanks for your input, feedback and guidance. brain[sic]
-----Original Message----- From: Ludovic Dubost [mailto:[email protected]] Sent: Tuesday, March 27, 2007 3:26 PM To: [email protected] Subject: Re: [xwiki-users] Scratchpad for howto on xwiki.org
Hi,
Ludovic
THOMAS, BRIAN M (ATTSI) a écrit :
Vincent, Sergiu, and the whole community:
My conversation begun by Gunther Leeb has continued offline and I've agreed to help him implement a solution similar to one I've created, which will probably be generally useful.
Ironically enough, we seem to have validated the old adage of the cobbler's children going barefoot - we're working on a feature of a Wiki, and though we have a community of interested users and developers and access to a Wiki, we began by still using a one-to-one email exchange.
In repentance thereof, I wish to nail down a page or three on xwiki.org to simultaneously develop, publish, and offer for comment the work we are doing.
Where would be the best place to put this? The topic is enhancing the LDAP authentication service implementation in the ways that Gunter needs, which would add a feature to discriminate on values in the LDAP-supplied user information.
brain[sic]
----------------------------------------------------------------------
--
-- You receive this message as a subscriber of the [email protected] mailing list. To unsubscribe: mailto:[email protected] For general help: mailto:[email protected]?subject=help ObjectWeb mailing lists service home page: http://www.objectweb.org/wws
-- Ludovic Dubost Blog: http://www.ludovic.org/blog/ XWiki: http://www.xwiki.com Skype: ldubost GTalk: ldubost AIM: nvludo Yahoo: ludovic
participants (5)
-
Gunter Leeb -
Ludovic Dubost -
THOMAS, BRIAN M (ATTSI) -
Vincent Massol -
Zeljko Trogrlic