diff options
author | James Moger <james.moger@gitblit.com> | 2014-02-21 15:25:46 -0500 |
---|---|---|
committer | James Moger <james.moger@gitblit.com> | 2014-02-21 15:25:46 -0500 |
commit | fa38a155cf2019c1fc7904ab47d37c0e7e558c13 (patch) | |
tree | f2855ed6fb1b2394d015c1ad7b4b40d78c75a73e /src/main/java/com/gitblit | |
parent | 308c9d40f106157b43add0869888a49dee5b9478 (diff) | |
download | gitblit-fa38a155cf2019c1fc7904ab47d37c0e7e558c13.tar.gz gitblit-fa38a155cf2019c1fc7904ab47d37c0e7e558c13.zip |
WindowsAuthProvider setting to restrict BUILTIN\Administrators
Some environments do not want to automatically allow Windows admin
accounts to be Gitblit admins. This patch allows disabling/enabling the
relationship between Windows builtin admin accounts and Gitblit accounts.
Diffstat (limited to 'src/main/java/com/gitblit')
-rw-r--r-- | src/main/java/com/gitblit/auth/WindowsAuthProvider.java | 8 |
1 files changed, 5 insertions, 3 deletions
diff --git a/src/main/java/com/gitblit/auth/WindowsAuthProvider.java b/src/main/java/com/gitblit/auth/WindowsAuthProvider.java index 93cae046..ac15b28f 100644 --- a/src/main/java/com/gitblit/auth/WindowsAuthProvider.java +++ b/src/main/java/com/gitblit/auth/WindowsAuthProvider.java @@ -158,9 +158,11 @@ public class WindowsAuthProvider extends UsernamePasswordAuthenticationProvider groupNames.add(group.getFqn()); } - if (groupNames.contains("BUILTIN\\Administrators")) { - // local administrator - user.canAdmin = true; + if (settings.getBoolean(Keys.realm.windows.permitBuiltInAdministrators, true)) { + if (groupNames.contains("BUILTIN\\Administrators")) { + // local administrator + user.canAdmin = true; + } } // TODO consider mapping Windows groups to teams |