- Support Markdown image links relative to the repository root (issue-324)
- Added filesystem write permission check (issue-345)
- Added GO launch parameter for redirecting logging to a rolling, daily log file (issue-348)
+ - Added settings to Windows authentication provider to permit/prohibit BUILTIN\Administrators from being Gitblit Admins (issue-354)
- Support rendering confluence, mediawiki, textile, tracwiki, and twiki markup documents
- Added setting to globally disable anonymous pushes in the receive pack
- Added a normalized diffstat display to the commit, commitdiff, and compare pages
- { name: 'realm.ldap.synchronize', defaultValue: 'false' }
- { name: 'realm.ldap.syncPeriod', defaultValue: '5 MINUTES' }
- { name: 'realm.ldap.removeDeletedUsers', defaultValue: 'true' }
+ - { name: 'realm.windows.permitBuiltInAdministrators', defaultValue: 'true' }
- { name: 'web.commitMessageRenderer', defaultValue: 'plain' }
- { name: 'web.documents', defaultValue: 'readme home index changelog contributing submitting_patches copying license notice authors' }
- { name: 'web.showBranchGraph', defaultValue: 'true' }
# SINCE 1.3.0\r
realm.windows.allowGuests = false\r
\r
+# Allow user accounts belonging to the BUILTIN\Administrators group to be\r
+# Gitblit administrators.\r
+#\r
+# SINCE 1.4.0\r
+realm.windows.permitBuiltInAdministrators = true\r
+\r
# The default domain for authentication.\r
#\r
# If specified, this domain will be used for authentication UNLESS the supplied\r
groupNames.add(group.getFqn());
}
- if (groupNames.contains("BUILTIN\\Administrators")) {
- // local administrator
- user.canAdmin = true;
+ if (settings.getBoolean(Keys.realm.windows.permitBuiltInAdministrators, true)) {
+ if (groupNames.contains("BUILTIN\\Administrators")) {
+ // local administrator
+ user.canAdmin = true;
+ }
}
// TODO consider mapping Windows groups to teams