diff --git a/config b/config index 3b791f5d..01cf8046 100644 --- a/config +++ b/config @@ -214,7 +214,7 @@ [group] # Group lookup method -# Value: none | htgroup +# Value: none | auth_type | htgroup type = none # Htgroup filename diff --git a/radicale/app/__init__.py b/radicale/app/__init__.py index 7643567e..ab685362 100644 --- a/radicale/app/__init__.py +++ b/radicale/app/__init__.py @@ -598,14 +598,17 @@ class Application(ApplicationPartDelete, ApplicationPartHead, user = "" if user: - if self.configuration.get("group", "type") != "none": + group_type = self.configuration.get("group", "type") + if group_type in ["htgroup"]: self._rights._user_groups = self._group.groups(login) if login else set([]) - elif self.configuration.get("auth", "type") == "ldap": - try: - logger.debug("Groups received from LDAP: %r", ",".join(self._auth._ldap_groups)) - self._rights._user_groups = self._auth._ldap_groups - except AttributeError: - pass + elif group_type in ["auth_type"]: + auth_type = self.configuration.get("auth", "type") + if auth_type in ["ldap", "pam"]: + try: + logger.debug("Groups received from %r: %r", auth_type, ",".join(self._auth._groups)) + self._rights._user_groups = self._auth._groups + except AttributeError: + pass # Create principal collection if user: diff --git a/radicale/auth/__init__.py b/radicale/auth/__init__.py index 7a79d246..314e4f56 100644 --- a/radicale/auth/__init__.py +++ b/radicale/auth/__init__.py @@ -106,7 +106,7 @@ class AuthContext: class BaseAuth: - _ldap_groups: Set[str] = set([]) + _groups: Set[str] = set([]) _urldecode_username: bool _lc_username: bool _uc_username: bool diff --git a/radicale/auth/ldap.py b/radicale/auth/ldap.py index c2f6efd2..cede4e6c 100644 --- a/radicale/auth/ldap.py +++ b/radicale/auth/ldap.py @@ -381,8 +381,8 @@ class Auth(auth.BaseAuth): tmp.append(rdns[0][1]) except Exception: tmp.append(g) - self._ldap_groups = set(tmp) - logger.debug("_login3 LDAP groups of user: %s", ",".join(self._ldap_groups)) + self._groups = set(tmp) + logger.debug("_login3 LDAP groups of user: %s", ",".join(self._groups)) if self._ldap_user_attr: if user_entry['attributes'][self._ldap_user_attr]: diff --git a/radicale/auth/pam.py b/radicale/auth/pam.py index 02727c85..0884fb20 100644 --- a/radicale/auth/pam.py +++ b/radicale/auth/pam.py @@ -97,6 +97,11 @@ class Auth(auth.BaseAuth): else: logger.debug("PAM user %r belongs to the required group: %r" % (login, self._group_membership)) + # add groups + members.append(primary_group) + self._groups = set(members) + logger.debug("PAM groups of user: %s", ",".join(self._groups)) + # Check the password if self.pam_authenticate(login, password, service=self._service): return login diff --git a/radicale/group/__init__.py b/radicale/group/__init__.py index 4cd8729d..92b2279b 100644 --- a/radicale/group/__init__.py +++ b/radicale/group/__init__.py @@ -29,6 +29,7 @@ from radicale import config, utils from radicale.log import logger INTERNAL_TYPES: Sequence[str] = ("none", + "auth_type", "htgroup", ) diff --git a/radicale/tests/test_group.py b/radicale/tests/test_group.py index e5f79352..cf4d0ee4 100644 --- a/radicale/tests/test_group.py +++ b/radicale/tests/test_group.py @@ -116,7 +116,7 @@ class TestBaseGroupRequests(BaseTest): "type": auth_type, "oauth2_token": "dummy", }, - "group": {"type": "auth-type"} + "group": {"type": "auth_type"} }) except RuntimeError: pass @@ -130,10 +130,9 @@ class TestBaseGroupRequests(BaseTest): {"auth": { "type": auth_type, }, - "group": {"type": "auth-type"} + "group": {"type": "auth_type"} }) except RuntimeError: raise else: pass -