sources/kerberos: add kiprop to ignored system principals (#11852) Co-authored-by: Marc 'risson' Schmitt <marc.schmitt@risson.space>
This commit is contained in:
committed by
GitHub
parent
3775e5b84f
commit
8c547589f6
@ -38,7 +38,7 @@ entries:
|
|||||||
name: "authentik default Kerberos User Mapping: Ignore system principals"
|
name: "authentik default Kerberos User Mapping: Ignore system principals"
|
||||||
expression: |
|
expression: |
|
||||||
localpart, realm = principal.rsplit("@", 1)
|
localpart, realm = principal.rsplit("@", 1)
|
||||||
denied_prefixes = ["kadmin/", "krbtgt/", "K/M", "WELLKNOWN/"]
|
denied_prefixes = ["kadmin/", "krbtgt/", "K/M", "WELLKNOWN/", "kiprop/", "changepw/"]
|
||||||
for prefix in denied_prefixes:
|
for prefix in denied_prefixes:
|
||||||
if localpart.lower().startswith(prefix.lower()):
|
if localpart.lower().startswith(prefix.lower()):
|
||||||
raise SkipObject
|
raise SkipObject
|
||||||
|
|||||||
Reference in New Issue
Block a user