group: introduce type auth_type, extend for PAM module

This commit is contained in:
Peter Bieringer
2026-07-19 14:35:18 +02:00
parent 912ea717a8
commit d9a0284996
7 changed files with 22 additions and 14 deletions

2
config
View File

@@ -214,7 +214,7 @@
[group]
# Group lookup method
# Value: none | htgroup
# Value: none | auth_type | htgroup
type = none
# Htgroup filename

View File

@@ -598,12 +598,15 @@ class Application(ApplicationPartDelete, ApplicationPartHead,
user = ""
if user:
if self.configuration.get("group", "type") != "none":
group_type = self.configuration.get("group", "type")
if group_type in ["htgroup"]:
self._rights._user_groups = self._group.groups(login) if login else set([])
elif self.configuration.get("auth", "type") == "ldap":
elif group_type in ["auth_type"]:
auth_type = self.configuration.get("auth", "type")
if auth_type in ["ldap", "pam"]:
try:
logger.debug("Groups received from LDAP: %r", ",".join(self._auth._ldap_groups))
self._rights._user_groups = self._auth._ldap_groups
logger.debug("Groups received from %r: %r", auth_type, ",".join(self._auth._groups))
self._rights._user_groups = self._auth._groups
except AttributeError:
pass

View File

@@ -106,7 +106,7 @@ class AuthContext:
class BaseAuth:
_ldap_groups: Set[str] = set([])
_groups: Set[str] = set([])
_urldecode_username: bool
_lc_username: bool
_uc_username: bool

View File

@@ -381,8 +381,8 @@ class Auth(auth.BaseAuth):
tmp.append(rdns[0][1])
except Exception:
tmp.append(g)
self._ldap_groups = set(tmp)
logger.debug("_login3 LDAP groups of user: %s", ",".join(self._ldap_groups))
self._groups = set(tmp)
logger.debug("_login3 LDAP groups of user: %s", ",".join(self._groups))
if self._ldap_user_attr:
if user_entry['attributes'][self._ldap_user_attr]:

View File

@@ -97,6 +97,11 @@ class Auth(auth.BaseAuth):
else:
logger.debug("PAM user %r belongs to the required group: %r" % (login, self._group_membership))
# add groups
members.append(primary_group)
self._groups = set(members)
logger.debug("PAM groups of user: %s", ",".join(self._groups))
# Check the password
if self.pam_authenticate(login, password, service=self._service):
return login

View File

@@ -29,6 +29,7 @@ from radicale import config, utils
from radicale.log import logger
INTERNAL_TYPES: Sequence[str] = ("none",
"auth_type",
"htgroup",
)

View File

@@ -116,7 +116,7 @@ class TestBaseGroupRequests(BaseTest):
"type": auth_type,
"oauth2_token": "dummy",
},
"group": {"type": "auth-type"}
"group": {"type": "auth_type"}
})
except RuntimeError:
pass
@@ -130,10 +130,9 @@ class TestBaseGroupRequests(BaseTest):
{"auth": {
"type": auth_type,
},
"group": {"type": "auth-type"}
"group": {"type": "auth_type"}
})
except RuntimeError:
raise
else:
pass