summaryrefslogtreecommitdiffstats
path: root/src/main/java
diff options
context:
space:
mode:
authorJames Moger <james.moger@gitblit.com>2014-02-21 15:25:46 -0500
committerJames Moger <james.moger@gitblit.com>2014-02-21 15:25:46 -0500
commitfa38a155cf2019c1fc7904ab47d37c0e7e558c13 (patch)
treef2855ed6fb1b2394d015c1ad7b4b40d78c75a73e /src/main/java
parent308c9d40f106157b43add0869888a49dee5b9478 (diff)
downloadgitblit-fa38a155cf2019c1fc7904ab47d37c0e7e558c13.tar.gz
gitblit-fa38a155cf2019c1fc7904ab47d37c0e7e558c13.zip
WindowsAuthProvider setting to restrict BUILTIN\Administrators
Some environments do not want to automatically allow Windows admin accounts to be Gitblit admins. This patch allows disabling/enabling the relationship between Windows builtin admin accounts and Gitblit accounts.
Diffstat (limited to 'src/main/java')
-rw-r--r--src/main/java/com/gitblit/auth/WindowsAuthProvider.java8
1 files changed, 5 insertions, 3 deletions
diff --git a/src/main/java/com/gitblit/auth/WindowsAuthProvider.java b/src/main/java/com/gitblit/auth/WindowsAuthProvider.java
index 93cae046..ac15b28f 100644
--- a/src/main/java/com/gitblit/auth/WindowsAuthProvider.java
+++ b/src/main/java/com/gitblit/auth/WindowsAuthProvider.java
@@ -158,9 +158,11 @@ public class WindowsAuthProvider extends UsernamePasswordAuthenticationProvider
groupNames.add(group.getFqn());
}
- if (groupNames.contains("BUILTIN\\Administrators")) {
- // local administrator
- user.canAdmin = true;
+ if (settings.getBoolean(Keys.realm.windows.permitBuiltInAdministrators, true)) {
+ if (groupNames.contains("BUILTIN\\Administrators")) {
+ // local administrator
+ user.canAdmin = true;
+ }
}
// TODO consider mapping Windows groups to teams